MIRAGE
Threat IntelligenceCVEs › CVE-2026-33017

CVE-2026-33017 — exposed on the internet

CVE-2026-33017: CWE-94: Improper Control of Generation of Code ('Code Injection') in langflow-ai langflow

Internet exposure observed by OffSeq scans · last 30 days

3
Exposed hosts
9.3
CVSS
96.2%
EPSS

Found on 3 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.

About CVE-2026-33017

On June 25, 2026, the first active exploitation of CVE-2026-55255, a critical CVSS 9.9 Langflow vulnerability, was documented. Langflow is an open-source framework for building AI agents and RAG pipelines. A single operator exploited both CVE-2026-55255 (cross-tenant IDOR) and CVE-2026-33017 (unauthenticated RCE, CVSS 9.3) against the same instance. Despite its lower score, the RCE has been exploited thousands of times and is listed in CISA KEV, while the IDOR showed no prior in-the-wild exploitation. The operator focused primarily on the RCE for code execution and implant delivery, using the IDOR opportunistically for credential theft across tenants. The financially motivated threat actor deployed a scripted loader to harvest AWS keys, environment files, and API credentials. This demonstrates that CVSS scores don't always correlate with real-world exploitation rates, as unauthenticated vulnerabilities require less effort than those needing authorization and disclosed object IDs.

Vendor: langflow-aiCWE-94CWE-95CWE-306

OffSeq internet scanning found CVE-2026-33017 on 3 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.

Exposed-host countries

Exposed via

http

Open the live CVE-2026-33017 view →

References