Skip to content
COOEY

EXPOSURES › CVE-2026-33017

CVE-2026-33017

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-33017 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildauth-bypasssupply-chain

Langflow allows unauthenticated public flow creation via code injection, enabling attackers to bypass security controls.

Langflow's code injection vulnerability permits building public flows without authentication, bypassing security controls and exposing sensitive data to unauthorized users. DIB organizations must audit all Langflow integrations and enforce strict access controls to prevent unauthorized access to critical workflows.

Shame score — The vulnerability allows unauthenticated access to critical functionality, representing a significant security control bypass that could lead to data exposure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.