Sysdig Documents Langflow CVE-2026-33017 Attack Timeline: Three-Phase Compromise in 20 Hours
Sysdig Threat Research published a detailed post-mortem of active CVE-2026-33017 exploitation against Langflow AI pipeline instances, documenting a three-phase attack timeline starting just 20 hours after disclosure with zero public PoC code. Phase 1: automated nuclei scanning with base64 exfiltration via interactsh. Phase 2: custom Python exploitation with pre-staged infrastructure deploying stage-2 payloads. Phase 3: data harvesting targeting LLM provider API keys (OpenAI, Anthropic), AWS credentials, database connection strings, and deployment configurations. The unauthenticated RCE (CVSS 9.3) in the public flow build endpoint executes arbitrary Python server-side without sandboxing — CISA set an April 8 federal remediation deadline.
Source
↳ Follow the thread