# CVE-2026-33017: How attackers compromised Langflow AI pipelines in 20 hours

DevFeed: [CVE-2026-33017: How attackers compromised Langflow AI pipelines in 20 hours](<https://devfeed.tech/articles/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours-53207.md>)

Original publisher: [Read original article](<https://webflow.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours>)

Author: Sysdig Threat Research Team

Published: 2026-03-19T00:00:00Z

Content type: article

Language: en

Sources: [Sysdig](<https://devfeed.tech/sources/sysdig-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Retrieval Augmented Generation (RAG)](<https://devfeed.tech/topics/retrieval-augmented-generation-rag.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [FastAPI](<https://devfeed.tech/topics/fastapi.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ai-pipeline-security](<https://devfeed.tech/tags/ai-pipeline-security.md>), [api](<https://devfeed.tech/tags/api.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-33017](<https://devfeed.tech/tags/cve-2026-33017.md>), [github](<https://devfeed.tech/tags/github.md>), [langflow](<https://devfeed.tech/tags/langflow.md>), [langflow-rce](<https://devfeed.tech/tags/langflow-rce.md>), [langflow-security-flaw](<https://devfeed.tech/tags/langflow-security-flaw.md>), [langflow-vulnerability](<https://devfeed.tech/tags/langflow-vulnerability.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [python](<https://devfeed.tech/tags/python.md>), [rag-security-risks](<https://devfeed.tech/tags/rag-security-risks.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [unauthenticated-rce-langflow-exploit](<https://devfeed.tech/tags/unauthenticated-rce-langflow-exploit.md>), [vulnerability-exploit-without-poc](<https://devfeed.tech/tags/vulnerability-exploit-without-poc.md>)

## AI overview

The article examines CVE-2026-33017, an unauthenticated remote code execution vulnerability in Langflow's public flow build endpoint. It reports that attackers began exploiting exposed instances about 20 hours after disclosure, using details from the advisory to execute arbitrary Python code and potentially access credentials and connected databases.

## Source excerpt

On March 17, 2026, a critical vulnerability was disclosed in Langflow, the open-source visual framework for building AI agents and Retrieval-Augmented Generation (RAG) pipelines. The vulnerability, CVE-2026-33017, is an unauthenticated remote code execution (RCE) in the public flow build endpoint that allows attackers to execute arbitrary Python code on any exposed Langflow instance, with no credentials required and only a single HTTP request to get moving.