LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-33017: Langflow Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 8, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-33017 to its Known Exploited Vulnerabilities catalog on Mar 25, 2026, with a federal patch deadline of Apr 8, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.

Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication. The issue affects deployments of the Langflow product and stems from missing controls that would normally restrict flow creation and code handling to authenticated users. This matters for IT and security teams because unauthenticated remote actors may gain the ability to introduce and execute code within the application environment, increasing the chance of unauthorized access or further compromise.

How it works

The weakness is classified under CWE-94, CWE-95, and CWE-306. These categories describe improper control of generated code, insufficient neutralization of directives in dynamically evaluated code, and missing authentication for critical functions.

An attacker can abuse the absence of authentication requirements on public flows to supply crafted input that results in code injection. The precise sequence of requests or parameters used depends on the implementation details of the affected flows.

Am I affected? How to find it in your systems

Langflow instances are the affected software. Locate all installations, including any running in cloud or containerized environments, by querying asset inventories, container registries, and network discovery tools for the product name.

Exact version numbers and configuration flags that trigger the vulnerability must be confirmed against the vendor advisory.

How to remediate

Apply mitigations per the instructions provided in the vendor advisory. Where the deployment uses cloud services, follow applicable BOD 22-01 guidance for securing those services.

If the required mitigations cannot be implemented, discontinue use of the product. After applying updates, re-audit all public flows to verify that authentication is now required.

If you can't patch immediately

Until the vendor mitigations are in place, restrict network access to Langflow instances through segmentation so that only authorized management networks can reach them.

These steps reduce exposure while plans are made to apply the official fixes or migrate away from the product.

If your data may have been exposed

Code injection vulnerabilities that permit unauthenticated access have been used to facilitate breaches in other products. Organizations can run a free exposure scan of their email addresses against known breach data to check for signs of prior compromise.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedLangflow · Langflow
WeaknessCWE-94
Added to CISA KEVMar 25, 2026
Federal patch deadlineApr 8, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities