CVE Tools

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

The Hacker NewsBy The Hacker News

Reported exploitedLangflow

Our summary

Attackers are exploiting CVE-2026-33017, an unauthenticated remote code execution issue in Langflow (CVSS 9.3), to gain initial access on internet-exposed AI application endpoints. Once triggered, the flaw enables deployment of a Monero cryptocurrency miner that disables host security components, persists via scheduling/cron, spreads through reused SSH credentials, and attempts to erase evidence. This matters because it turns reachable Langflow instances into a new entry point for commodity cryptojacking into enterprise environments.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store