THREAT OPS › CVEs › CVE-2026-33017
CVE-2026-33017 — Langflow Code Injection Vulnerability
Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.
Vulnerability details
- Affected productsLangflow
- KEV remediation due2026-04-08
Exploiting threat actors
- TurlaG0010
Related reporting
- August 2026 CVE Landscaperecordedfuture
- The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposuretenable
- Metasploit Wrap Up: Lot of summer shells and fit http profilesrapid7
- 29th June – Threat Intelligence Reportcheckpoint_research
- 22nd June – Threat Intelligence Reportcheckpoint_research