INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Langflow Vulnerability Exploited for Unauthenticated RCE
| 2026-06-10 15:00 CRITICAL HIGH EXPLOITED VULNERABILITY ATTACK ON AI SYSTEMS
Executive Summary
AI-generated
The Langflow vulnerability, CVE-2026-5027, has been exploited in the wild for unauthenticated remote code execution. This high-severity security flaw allows attackers to write files to arbitrary locations on the filesystem using path traversal sequences. The vulnerability was discovered by Tenable and identified as a case of path traversal that could enable an attacker to execute malicious commands. Langflow instances exposed online, with approximately 7,000 publicly accessible, are vulnerable in North America. This incident underscores a growing trend of attackers targeting infrastructure and tooling used for building AI applications.
Technical Mitigations AI-generated
• Sanitize input parameters, especially those related to file uploads or downloads.
• Validate user-supplied data before using it for API requests.
• Implement secure authentication mechanisms to prevent unauthenticated access.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
MuddyWaterMuddyWater
CVE-2026-21445CVE-2026-21445
CVE-2025-3248CVE-2025-3248
CVE-2026-33017CVE-2026-33017
CVE-2025-34291CVE-2025-34291
CVE-2026-5027CVE-2026-5027
CVE-2026-0770CVE-2026-0770
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
2025/06/10
Threat actors used a path traversal flaw in the VulnCheck software to target CVE-2025-3248 vulnerabilities.
Click on any entity below to view its context and source!
source_region
Iran, Islamic Republic of
Last year, the U.S. Cybersecurity & Infrastructure Security Agency (CISA) also warned about
active exploitation of CVE-2025-3248
, for which Condon says VulnCheck continues to observe activity, including activity linked to the Iranian threat group MuddyWater.
threat_actor
MuddyWater
Last year, the U.S. Cybersecurity & Infrastructure Security Agency (CISA) also warned about
active exploitation of CVE-2025-3248
, for which Condon says VulnCheck continues to observe activity, including activity linked to the Iranian threat group MuddyWater.
vulnerability
CVE-2025-3248
Last year, the U.S. Cybersecurity & Infrastructure Security Agency (CISA) also warned about
active exploitation of CVE-2025-3248
, for which Condon says VulnCheck continues to observe activity, including activity linked to the Iranian threat group MuddyWater.
attribution
CVE-2025
Last year, the U.S. Cybersecurity & Infrastructure Security Agency (CISA) also warned about
active exploitation of CVE-2025-3248
, for which Condon says VulnCheck continues to observe activity, including activity linked to the Iranian threat group MuddyWater.
February 2026
Threat actors exploited a path traversal flaw in Langflow attacks to target the project maintainers.
March 27, 2026
Threat actors exploited a path traversal flaw in Langflow attacks to gain unauthorized access.
Click on any entity below to view its context and source!
organisation
Langflow
Tenable publicly disclosed the issue on March 27, 2026, more than two months after initially reporting it to the Langflow team without receiving a response.
March 27
Threat actors used a path traversal flaw in Langflow attacks to target the project maintainers.
late March 2026
Threat actors exploited a path traversal flaw in Langflow attacks by writing files to arbitrary locations on the filesystem using ../.
March 30, 2026
Threat actors exploited a path traversal flaw in the langflow-base package version 0.8.3 to gain unauthorized access.
Click on any entity below to view its context and source!
infrastructure
1.9.0
Although Tenable did not mention a fix in its advisory,
Snyk Security reported
on March 30, 2026, that the issue was fixed in the langflow-base package version 0.8.3, while the Langflow application itself received a patch in version 1.9.0.
infrastructure
0.8.3
Although Tenable did not mention a fix in its advisory,
Snyk Security reported
on March 30, 2026, that the issue was fixed in the langflow-base package version 0.8.3, while the Langflow application itself received a patch in version 1.9.0.
organisation
Snyk Security
Although Tenable did not mention a fix in its advisory,
Snyk Security reported
on March 30, 2026, that the issue was fixed in the langflow-base package version 0.8.3, while the Langflow application itself received a patch in version 1.9.0.
April 15, 2026
Langflow version 1.9.0 was released on April 15, 2026.
Click on any entity below to view its context and source!
infrastructure
1.9.0
Update
When reached for comment regarding the patch status, Tenable told The Hacker News via email that the project maintainer of the langflow-base package confirmed the vulnerability was addressed in
Langflow version 1.9.0
released on
April 15, 2026
.
Jun 10, 2026
Threat actors exploited a path traversal flaw in Langflow attacks to gain unauthorized access.
2026/06/10
Langflow users are advised to upgrade their software from version 1.10.0, published on June 10, 2026.
Click on any entity below to view its context and source!
infrastructure
1.10.0
Langflow users are recommended to upgrade to the latest release,
version 1.10.0
, published earlier today.
2026/06/10
The Iranian state-sponsored group known as MuddyWater exploited a high-severity path traversal flaw in Langflow's file upload functionality to target vulnerable instances of the platform.
Click on any entity below to view its context and source!
organisation
Langflow Vulnerability CVE-2026-5027 Exploited
Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE.
organisation
CVE-2026-5027
CVE-2026-5027 is a high-severity path traversal flaw in Langflow's file upload functionality that fails to properly sanitize user-supplied filenames.
organisation
CVE-2026
Exploitation of CVE-2026-5027 comes shortly after similar activity targeting other Langflow vulnerabilities earlier this year, including CVE-2026-0770, CVE-2026-21445, and
CVE-2026-33017
.
organisation
VulnCheck
Caitlin Condon, vice president of security research at VulnCheck, said in a LinkedIn post that the vulnerability enables remote code execution.
organisation
Censys
Data from Censys shows that there are about 7,000 Langflow instances publicly exposed on the internet, with a majority of them located in North America.
Condon added that Censys scans identified roughly 7,000 publicly exposed Langflow instances.
organisation
Langflow
Data from Censys shows that there are about 7,000 Langflow instances publicly exposed on the internet, with a majority of them located in North America.
organisation
Condon
Condon added that Censys scans identified roughly 7,000 publicly exposed Langflow instances.
threat_actor
MuddyWater
The attack effort follows a flurry of exploitation activity targeting other Langflow vulnerabilities this year, including
CVE-2026-0770
,
CVE-2026-33017
,
CVE-2026-21445
, and
CVE-2025-34291
, the last of which has been weaponized by the Iranian state-sponsored group known as MuddyWater.
organisation
The Hacker News
"The activity underscores a growing trend of attackers targeting the infrastructure and tooling that organizations use to build and deploy AI applications," the company said in a statement shared with The Hacker News.
organisation
Retrieval-Augmented Generation (RAG
Langflow is an open-source visual platform for building AI applications, AI agents, Retrieval-Augmented Generation (RAG) systems, and MCP-based workflows using a drag-and-drop interface instead of traditional coding.
organisation
MCP
Langflow is an open-source visual platform for building AI applications, AI agents, Retrieval-Augmented Generation (RAG) systems, and MCP-based workflows using a drag-and-drop interface instead of traditional coding.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Tactical Metrics
Metrics
infrastructure
1.9.0
Software Version
Click for context!
…When reached for comment regarding the patch status, Tenable told The Hacker News via email that the project maintainer of the langflow-base package confirmed the vulnerability was addressed in
Langflow version 1.9.0
released on
April 15, 2026
.
Although Tenable did not mention a fix in its advisory,
Snyk Security reported
on March 30, 2026, that the issue was fixed in the langflow-base package version 0.8.3, while the Langflow application itself received a patch in version 1.9.0.
Metrics
infrastructure
0.8.3
Software Version
Although Tenable did not mention a fix in its advisory,
Snyk Security reported
on March 30, 2026, that the issue was fixed in the langflow-base package version 0.8.3, while the Langflow application itself received a patch in version 1.9.0.
Metrics
infrastructure
1.10.0
Software Version
Langflow users are recommended to upgrade to the latest release,
version 1.10.0
, published earlier today.
Intelligence Sources
The Hacker News
2026-06-10
BleepingComputer
2026-06-10
Path traversal flaw in AI dev platform Langflow exploited in attacks
BleepingComputer
The Hacker News
2026-06-10
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
Langflow Vulnerability CVE-2026-5027 Exploited
entity
10x
timeline
Temporal Reference
Jun 10, 2026
date
6x
vulnerability
Exploited CVE
CVE-2026-5027
cve
5x
attribution
Attributing Entity
CVE-2026
authority
3x
infrastructure
Software Version
1.9.0
version
2x
general metric
Jun
10
jun
2x
general metric
%
54
%
Contextual Telemetry
Context Block
9 METRICS
general metric
Score
9
score
tactic
Cyber Operation Type
Remote Code Execution
tactic
target region
Target Region
NORTH_AMERICA
region
general metric
Langflow Instances
7,000
langflow instances
source region
Origin Country
Iran, Islamic Republic of
country
threat actor
APT Group
MuddyWater
actor
general metric
Cve-2026
5,027
cve-2026
general metric
Stars
149,000
stars
general metric
Forks
9,200
forks
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.