CVE-2026–17633 - Authenticated RCE in Langflow OSS via /api/v1/custom_component
This story is from 2026-09-21. It is preserved in the archive; the latest stories are on the live feed.
Summary Field Value CVE ID CVE-2026-17633 CVSS 8.5 (HIGH) CWE CWE-94 (Improper Control of Generation of Code) Affected Langflow OSS 1.0.0 – 1.10.3 Preconditions Any authenticated user + LANGFLOW_ALLOW_CUSTOM_COMPONENTS=true Vulnerable endpoint POST /api/v1/custom_component Langflow is an open-sourc…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-21 23:06 · DEV Community — AI
CVE-2026–17633 - Authenticated RCE in Langflow OSS via /api/v1/custom_component
More stories
- Higgsfield AI ships new video features in a day with GPT-6 Astra — OpenAI News
- Amazon blocks Meta’s Muse AI agent — The Verge AI
- Grok 4.7 — Hacker News Front Page
- Google says its Gemini AI model hacked three other companies — The Guardian AI
- Anthropic, OpenAI, SpaceXAI, Google sued over call to ‘pace’ AI development — Politico Technology
- British Columbia Sues OpenAI Over Canada Mass Shooting Warning Failure — Bloomberg AI
- Python Workers are now generally available — Cloudflare Blog — AI
- Moonshot’s Kimi K3 lands on Amazon in key test for Chinese open-source AI revenue — South China Morning Post Tech
Get the daily brief of stories like this at 6:30 every morning →