Critical Langflow RCE Flaw Lets Prompt Injection Take Over Servers
Langflow is an open-source, low-code AI workflow platform that can connect large language models with CSV data to build agents. Its CSV Agent hard-codes allow_dangerous_code as True, automatically enabling LangChain's Python REPL. If the service is exposed to the internet, a malicious prompt can execute Python and operating-system commands, putting data, keys and control of the host at risk.
GitHub disclosed CVE-2026-27966 on February 26, 2026. It carries a CVSS 3.1 score of 9.8 and affects all versions before 1.8.0; Langflow patched it in version 1.8.0. Separately, the vulnerability that Sysdig detected being exploited on March 18, about 20 hours after disclosure, was CVE-2026-33017. Six IP addresses attempted attacks within two days, and the patched version for that flaw is 1.9.0.
All Coverage
3 original reportsThe Backstory
The history behind this eventCISA Warns Critical Langflow Flaw CVE-2026-33017 Is Being Exploited
Langflow is an open-source development tool for building large language model (LLM) applications and is often connected to cloud services, models and data sources. If remotely compromised, it could give attackers access to AI infrastructure and sensitive credentials, extending the impact beyond a single host.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned in July 2026 that CVE-2026-33017 was being actively exploited. The vulnerability has a CVSS score of 9.3 and affects Langflow versions before 1.8.1. Attackers have used it to steal AI and cloud access keys and mine Monero, and users should upgrade to version 1.9.0 as soon as possible.
Attackers Exploit Langflow Path-Traversal Flaw
Langflow is a development tool for building large-language-model applications. Its path-traversal vulnerability, CVE-2026-5027, allows unauthenticated attackers to access server files and potentially execute arbitrary code remotely. The flaw could compromise deployed AI applications, credentials and internal data, posing a significant risk to development and operations teams.
A cybersecurity company recently confirmed that attackers have used CVE-2026-5027 in real-world intrusions in 2026, taking it beyond the proof-of-concept stage. Langflow’s developers patched the vulnerability in version 1.9.0. Organizations running older versions should upgrade as soon as possible and review server file access, anomalous processes and outbound connection logs.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.