#Langflow
All CosmicBytez Labs articles tagged #Langflow, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-85025: Langflow MCP Endpoint Flaw Enables Unauthenticated RCE
Langflow OSS 1.0.0-1.11.5 lets unauthenticated attackers run arbitrary code via public MCP project endpoints due to broken session isolation.
- News
Critical Langflow Flaw Exploited to Steal OpenAI and AWS Keys
Attackers are exploiting unauthenticated RCE in Langflow (CVE-2026-0768) to harvest OpenAI and AWS credentials from exposed AI-agent servers.
- Newsletter
Weekly Digest — Issue #33
ShinyHunters' deadline hits as McKesson confirms a breach, a critical Langflow RCE bleeds AI-agent keys, and PaperCut's patched zero-days pivot to data theft.
- Security
Critical RCE in IBM Langflow OSS via Unauthenticated A2A Endpoint
CVE-2026-19286 (CVSS 9.8) lets remote attackers execute arbitrary code on Langflow OSS 1.0.0-1.11.1 through the public A2A endpoint, no auth needed.
- Security
IBM Langflow OSS Flaw Lets Authenticated Users Escalate to Full RCE
CVE-2026-19295 (CVSS 9.9) lets an authenticated Langflow user run arbitrary OS commands by crafting a flow, bypassing the custom-component lockdown.
- News
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog on August 5, 2026 — a critical Langflow RCE, an Apache Tomcat encryption...
- Security
CVE-2026-9198: IBM Langflow Code Injection Vulnerability
A critical unauthenticated code injection flaw in Langflow 1.0.0–1.10.0 allows attackers to chain two API endpoints to obtain a SUPERUSER token and...
- News
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Sysdig researchers link a second Langflow server attack to JADEPUFFER, an AI-agent-driven threat operator now deploying ENCFORGE — a Go-based ransomware...
- Security
CVE-2026-13446: IBM Langflow Hardcoded Credentials (CVSS 9.8)
IBM Langflow OSS versions 1.0.0 through 1.10.1 contain hardcoded credentials used for inbound authentication and internal encryption, allowing...
- News
CISA Orders Feds to Prioritize Patching Langflow Auth Bypass Flaw
CISA added CVE-2026-55255, a CVSS 9.9 IDOR authorization bypass in Langflow, to its Known Exploited Vulnerabilities catalog on July 7, ordering U.S....
- News
JadePuffer: The First Fully Autonomous LLM-Driven Ransomware Attack
Security researchers at Sysdig have documented JadePuffer — an agentic threat actor powered entirely by a large language model that independently...
- News
Agentic AI Used to Conduct Ransomware Attack via Langflow Vulnerability
Threat group JadePuffer leveraged an LLM agent to autonomously execute a multi-stage ransomware-style attack through a critical Langflow vulnerability,...
- News
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Sysdig researchers documented the first fully autonomous AI-driven ransomware campaign, where threat actor JADEPUFFER used an AI agent to chain Langflow...
- News
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
Threat actors are actively weaponizing CVE-2026-33017, a critical unauthenticated RCE flaw in Langflow, to deploy a Monero miner via the lambsys...
- Newsletter
June 30 Digest: BlueHammer Zero-Day, Ransomware Goes Corporate, AI Supply Chain Risks & Nation-State ICS Threats
A Microsoft Defender zero-day fuels ransomware before any patch exists; researchers dissect how syndicate groups run HR departments and tiered pricing;...
- News
Path Traversal Flaw in AI Dev Platform Langflow Exploited in Attacks
Attackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in Langflow, to write arbitrary files on exposed servers....
- News
Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE
A high-severity path traversal flaw (CVE-2026-5027, CVSS 8.8) in the AI application builder Langflow is being actively exploited with no patch available....
- Security
CVE-2025-34291: Langflow Origin Validation Error
CISA adds CVE-2025-34291 to the Known Exploited Vulnerabilities catalog — an overly permissive CORS configuration combined with a SameSite=None refresh...
- News
CISA: New Langflow Flaw Actively Exploited to Hijack AI
CISA has added CVE-2026-33017, a critical unauthenticated remote code execution vulnerability in the Langflow AI framework, to its Known Exploited...