Summary
CVE-2026-33017 is an unauthenticated RCE in Langflow’s POST /api/v1/build_public_tmp/{flow_id}/flow endpoint, allowing arbitrary Python execution on exposed AI agent/RAG pipeline instances. Sysdig TRT recorded exploitation within 20 hours of disclosure, with attackers stealing cloud API keys and database credentials. Langflow has 145K+ GitHub stars; added to CISA KEV catalog March 25, 2026 — but many self-hosted instances may remain unpatched.
PreScreening Notes
Score: 9/10 — critical priority
Actively exploited unauthenticated RCE in popular open-source AI/RAG tool.
Research Notes
Additional Sources Found
- 2026-06-25-langflow-csa-research-note — CSA technical analysis, exploitation phases
- 2026-06-25-langflow-nvd-detail — NVD CVSS 9.3, CWE-94
- 2026-06-25-langflow-endorlabs-analysis — Code-level root cause analysis
- 2026-06-25-langflow-cisa-kev-listing — CISA KEV addition March 25, 2026; federal patch deadline April 8 (BOD 22-01)
Key Facts Verified
- Confirmed: Unauthenticated RCE via optional
dataparam onbuild_public_tmpendpoint - Confirmed: Sysdig exploitation within ~20 hours; cloud API key and DB credential theft
- Confirmed: Fixed in Langflow 1.9.0; distinct from CVE-2025-3248 (also in CISA KEV)
- Confirmed: CISA added CVE-2026-33017 to KEV catalog March 25, 2026 — federal deadline April 8, 2026
- Ongoing risk: Self-hosted instances pre-1.9.0 with public exposure remain vulnerable despite KEV listing
Warning
Original disclosure March 2026 — not breaking same-week CVE. Story angle: ongoing exposure despite KEV listing, not “KEV gap.” Many Turkish teams may run unpatched self-hosted Langflow.
Broader Context
Second major langflow RCE pattern signals ai-agent-security gap in self-hosted rag infrastructure. Complements akrites industry response to AI-accelerated vulnerability discovery.
Related Wiki Pages
langflow, rag, llm-applications, ai-agent-security, supply-chain-security, agentic-ai, zero-day-vulnerabilities, vulnerability
Editorial Notes
Onaylanan açı: CISA KEV listesine eklenmesine rağmen self-hosted Langflow instance’larında devam eden maruziyet — “KEV gap” değil, yama uygulanmamış production riski.
Format: brief — acil güvenlik uyarısı; teknik detay + eylem maddeleri.
Reporting talimatları:
- CVE-2026-33017’nin Mart 2025 KEV eklenmesi ile federal deadline (8 Nisan) tarihlerini net ver
- “Yeni CVE” olarak çerçeveleme; açı 3 ay sonra hâlâ patchsiz instance’lar
- Türk geliştirici ekipleri için self-hosted RAG/agent pipeline riskini vurgula
- Langflow 1.9.0+ yama gereksinimini belirt
- akrites ile bağlantı kur: AI-hızlandırılmış keşif vs. yavaş yama döngüsü
Başlık önerileri:
- Langflow RCE: CISA uyarısına rağmen self-hosted AI pipeline’ları hâlâ hedefte
- CVE-2026-33017: Popüler RAG aracında yamalanmamış instance’lar aktif sömürüde
- AI agent altyapısında Langflow açığı: API anahtarları ve DB credential’ları çalınıyor
Makalede mutlaka yer almalı:
- Unauthenticated RCE, POST
/api/v1/build_public_tmp/{flow_id}/flow - Sysdig TRT: açıklamadan ~20 saat içinde sömürü
- 145K+ GitHub star, CISA KEV (25 Mart 2026)
- Bulut API key ve veritabanı credential hırsızlığı
- Self-hosted instance’lar için acil yama kontrol listesi
Draft Article
Published: langflow-cve-2026-33017-rce-exploited