TGViewer
zerodayalpha zerodayalpha @zerodaytraining · 1.5K subscribers
Post #227 916
⚡️ 0-Day Alert: IBM LangFlow OSS RCE

LangFlow deployments have been under active exploitation since May.

CVE-2025-34291: CORS misconfiguration + SameSite=None
CVE-2026-33017*: Unauthenticated RCE via build_public_tmp's data parameter
CVE-2026-55255: IDOR in /api/v1/responses: run any user's flow by ID
CVE-2026-0770: Unauthenticated RCE via validate_code() / decorator abuse
CVE-2026-9198: Unauthenticated RCE via auto_login + validate/code chain

Bugs are not hard, likely spotted by generally available AI. Public exploit POCs exist.

Majority pattern: takes input from an API endpoint variable and executes it directly on the OS.

Attack pattern suggests that LangFlow has not seen appropriate security hardening from the vendor, and shouldn't be deployed in environments where an arbitrary code execution poses a risk.

* Attached: 33017 diff and code trace to exec()
  • ❤ 1
More from @zerodaytraining
  1. Sep 15, 2026⚡️ 0-Day Alert: Chrome v8 RCE CVE-2026-87491: WasmGetOwnProperty builtin may invoke a gett…
  2. Sep 8, 2026⚡️ 0-Day Alert: Chrome v8 RCE exploited in the wild CVE-2026-85046: v8 array-builtin callb…
  3. Aug 29, 2026Browser Exploit Surface model + bug overlay CVE callouts: randomly picked exploitable bug…
  4. Aug 21, 2026Mastery container: Multi-Specialization Essentials A curated course of foundational webina…
  5. Aug 5, 2026"In an era where autonomous AI agents are increasingly being used for vulnerability huntin…
  6. Aug 3, 2026⚡️ Linux Kernel just issued a single-fix security update for stable LTS branches, addressi…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →