{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/citrix-netscaler/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Siyuan","Langflow \u003c= 1.8.2","Langflow (\u003c 1.3.4)","n8n (\u003c 1.121.0)","Citrix NetScaler","Marimo notebook","Apache Tomcat"],"_cs_severities":["critical"],"_cs_tags":["langflow","rce","cve-2026-33017","ai-pipeline"],"_cs_type":"threat","_cs_vendors":["B3log","Langflow","n8n","Citrix","Marimo","Apache"],"content_html":"\u003cp\u003eA critical remote code execution vulnerability, CVE-2026-33017, affects Langflow AI pipelines prior to version 1.9.0. Langflow is a tool used for building and deploying AI-powered agents and workflows. The vulnerability resides in the \u003ccode\u003ebuild_public_tmp\u003c/code\u003e endpoint, which is intended to be unauthenticated for public flows. However, it incorrectly accepts attacker-supplied flow data, leading to remote code execution with full server process privileges. The vulnerability can be exploited by an unauthenticated remote attacker if the Langflow instance has at least one public flow, a common setup for demos and chatbots. Security researchers have reported that this vulnerability is actively exploited and targeted by scanning activity, making immediate patching or mitigation essential.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker sends a malicious request to the \u003ccode\u003e/build_public_tmp\u003c/code\u003e endpoint of a vulnerable Langflow instance.\u003c/li\u003e\n\u003cli\u003eThe Langflow server incorrectly processes the attacker-supplied flow data without proper validation.\u003c/li\u003e\n\u003cli\u003eThe server executes attacker-controlled code due to the lack of authentication and input sanitization on the \u003ccode\u003ebuild_public_tmp\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe attacker gains full server process privileges.\u003c/li\u003e\n\u003cli\u003eThe attacker establishes persistence by modifying system files or creating new user accounts.\u003c/li\u003e\n\u003cli\u003eThe attacker accesses sensitive flow data, including API keys, credentials, and confidential information.\u003c/li\u003e\n\u003cli\u003eThe attacker pivots to other internal systems by leveraging the compromised Langflow instance as a jump host.\u003c/li\u003e\n\u003cli\u003eThe attacker exfiltrates sensitive data or deploys malware, such as ransomware, to disrupt operations.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-33017 allows an unauthenticated attacker to achieve remote code execution with full server process privileges, impacting availability, integrity, and confidentiality. This can lead to complete system compromise, data breaches, and potential financial losses. Given the active exploitation and targeted scanning activity reported by security researchers, organizations using vulnerable Langflow instances are at immediate risk. The vulnerability allows the attacker to access sensitive data, deploy malware, and disrupt critical AI-powered workflows.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately patch Langflow instances to version 1.9.0 or later to remediate CVE-2026-33017, as recommended by the vendor advisory.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to limit the blast radius of a potential compromise stemming from CVE-2026-33017.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule targeting suspicious processes spawned by the Langflow process to detect exploitation attempts.\u003c/li\u003e\n\u003cli\u003eEnable process monitoring and audit logging on Langflow servers to enhance detection capabilities.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for unusual outbound connections from Langflow servers, which could indicate post-exploitation activity.\u003c/li\u003e\n\u003cli\u003eReview and restrict access to public flows to minimize the attack surface, as exploitation requires at least one public flow.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T13:37:43Z","date_published":"2026-03-24T12:00:00Z","id":"https://feed.craftedsignal.io/briefs/2026-03-langflow-rce/","summary":"A critical remote code execution vulnerability, CVE-2026-33017, exists in Langflow AI pipelines prior to version 1.9.0 that allows an unauthenticated remote attacker to execute code with full server process privileges, impacting availability, integrity, and confidentiality.","title":"Critical RCE Vulnerability in Langflow AI Pipelines (CVE-2026-33017)","url":"https://feed.craftedsignal.io/briefs/2026-03-langflow-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Citrix NetScaler","version":"https://jsonfeed.org/version/1.1"}