<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/langflow-rce-actively-exploited-to-deploy-cryptominers-on-ai-infrastructure-etl1ohlb0" -->

---
title: Langflow RCE Actively Exploited to Deploy Cryptominers...
description: A critical unauthenticated RCE vulnerability (CVE-2026-33017, CVSS 9.8) in Langflow, the open-source AI application builder, is being actively exploited in the...
canonical: https://daily.dev/posts/langflow-rce-actively-exploited-to-deploy-cryptominers-on-ai-infrastructure-etl1ohlb0
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Langflow RCE Actively Exploited to Deploy Cryptominers on AI Infrastructure | daily.dev
og:description: A critical unauthenticated RCE vulnerability (CVE-2026-33017, CVSS 9.8) in Langflow, the open-source AI application builder, is being actively exploited in the...
og:url: https://daily.dev/posts/langflow-rce-actively-exploited-to-deploy-cryptominers-on-ai-infrastructure-etl1ohlb0
og:image: https://api.daily.dev/og/posts/ETL1OhLb0.png
og:image:alt: Langflow RCE Actively Exploited to Deploy Cryptominers on AI Infrastructure
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Langflow RCE Actively Exploited to Deploy Cryptominers on AI Infrastructure

**[Orca Security Blog](https://daily.dev/sources/orca-security-blog)** · 3 min read · 0 upvotes · 0 comments

## Summary

A critical unauthenticated RCE vulnerability (CVE-2026-33017, CVSS 9.8) in Langflow, the open-source AI application builder, is being actively exploited in the wild. Attackers can execute arbitrary Python code via a single HTTP POST request to a public API endpoint with no authentication required. An active campaign observed over 19 days deployed 'lambsys,' a Go-based binary that kills rival cryptominer processes, disables security controls (AppArmor, SELinux, UFW, iptables), wipes logs, and installs a customized XMRig Monero miner. The malware also harvests environment variables, .env files, database credentials, and API keys. Approximately 7,000 internet-accessible Langflow servers were identified as exposed. All versions up to and including 1.8.2 are affected — users must upgrade to version 1.9.0 immediately. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog. Rotate all credentials on previously exposed instances and monitor for outbound connections to 83.142.209[.]214.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://orca.security/resources/blog/langflow-rce-vulnerability-cve-2026-33017>

## Similar posts on daily.dev

- [From Langflow to Monero: Inside CVE-2026-33017 Cryptominer](https://daily.dev/posts/from-langflow-to-monero-inside-cve-2026-33017-cryptominer-yaxregtae) · Trend Micro · 0 upvotes · 0 comments
- [Langflow RCE under active attack months after a patch was shipped](https://daily.dev/posts/langflow-rce-under-active-attack-months-after-a-patch-was-shipped-jzjannqnb) · CSO Online · 0 upvotes · 0 comments
- [Critical Langflow Vulnerability Allows Remote Code Execution](https://daily.dev/posts/critical-langflow-vulnerability-allows-remote-code-execution-vnn8uugk6) · AI Cyber Insights · 1 upvotes · 0 comments
- [Critical Flaw in Langflow AI Platform Under Attack](https://daily.dev/posts/critical-flaw-in-langflow-ai-platform-under-attack-fz5dbqsfo) · Dark Reading · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#ai-infrastructure](https://daily.dev/tags/ai-infrastructure)

[View this post on daily.dev](https://daily.dev/posts/langflow-rce-actively-exploited-to-deploy-cryptominers-on-ai-infrastructure-etl1ohlb0)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Langflow RCE Actively Exploited to Deploy Cryptominers on AI Infrastructure","url":"https://daily.dev/posts/langflow-rce-actively-exploited-to-deploy-cryptominers-on-ai-infrastructure-etl1ohlb0","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/langflow-rce-actively-exploited-to-deploy-cryptominers-on-ai-infrastructure-etl1ohlb0"},"datePublished":"2026-07-01T18:25:54.224Z","dateModified":"2026-07-01T18:26:22.275Z","description":"A critical unauthenticated RCE vulnerability (CVE-2026-33017, CVSS 9.8) in Langflow, the open-source AI application builder, is being actively exploited in the...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e6f6c2f41e9b858c2f23cdb738ee7c0a?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e6f6c2f41e9b858c2f23cdb738ee7c0a?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Orca Security Blog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Orca Security Blog","logo":"https://media.daily.dev/image/upload/s--kkQFNboJ--/f_auto,q_auto/v1780213281/logos/orca-security-blog?_a=BAMAMiWQ0","url":"https://daily.dev/sources/orca-security-blog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/langflow-rce-actively-exploited-to-deploy-cryptominers-on-ai-infrastructure-etl1ohlb0","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,ai-infrastructure","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Orca Security Blog","item":"https://daily.dev/sources/orca-security-blog"},{"@type":"ListItem","position":3,"name":"Langflow RCE Actively Exploited to Deploy Cryptominers on AI Infrastructure"}]}
```

