[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fIuHVkBOyijmYgHuS7g355XB-i5AxKEk0Y-etMZ38EeM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"37586cc9-5802-4e1a-a51c-97b5e27b6d83","code-injection-vulnerability-in-langflow-actively-exploited","b1f61fa0-0fa0-4967-93b5-db9218669f91","Code Injection Vulnerability in Langflow Actively Exploited","A code injection vulnerability (CVE-2026-33017) in Langflow has been added to CISA's Known Exploited Vulnerabilities catalog due to active exploitation in the wild. Code injection vulnerabilities allow attackers to execute malicious code on vulnerable systems, potentially leading to complete system compromise. The addition to the KEV catalog indicates that threat actors are actively targeting this vulnerability, making it a high-priority security risk. Federal agencies are now required to remediate this vulnerability under BOD 22-01, highlighting the critical nature of the threat.","**Immediate actions:**\n- This incident could have been prevented through robust vulnerability management practices including continuous vulnerability scanning to identify the flaw early, prompt patch deployment once fixes became available, and implementation of input validation controls to prevent code injection attacks\n- Organizations should maintain an inventory of all applications like Langflow, subscribe to security advisories from vendors, and establish processes to rapidly deploy security patches especially for internet-facing applications\n\n**Long-term improvements:**\n- implementing application security controls such as input sanitization and code review processes during development could prevent such vulnerabilities from being introduced initially",[12,13,14,15,16,17],"CIS Control 7","NIST SP 800-40","NIST SP 800-53 SI-2","NIST SP 800-53 SI-3","CIS Control 2","OWASP Top 10","published","2026-03-25T19:08:08.02367+00:00","2026-03-25T19:08:07.897+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F03\u002F25\u002Fcisa-adds-one-known-exploited-vulnerability-catalog","cisa-adds-one-known-exploited-vulnerability-to-catalog-6","CISA Adds One Known Exploited Vulnerability to Catalog",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":33,"name":34,"slug":35,"description":36,"color":37},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]