Using AI to code does not mean your code is more secure • The Register

0

As more people use AI tools to write code, the tools themselves are introducing more vulnerabilities.

Researchers affiliated with Georgia Tech SSLab have been tracking CVEs attributable to flaws in AI-generated code

Last August, they found just two CVEs that could be definitively linked to Claude Code – CVE-2025-55526, a 9.1 severity directory traversal vulnerability in n8n-workflows, and GHSA-3j63-5h8p-gf7c, an improper input handling bug in the x402 SDK.

In March, they identified 35 CVEs – 27 of which were authored by Claude Code, 4 by GitHub Copilot, 2 by Devin, and 1 each by Aether and Cursor.

Claude Code’s overrepresentation appears to follow from its recent surge in popularity. In the past 90 days, Claude Code has added more than 30.7 billion lines of code to public repositories, according to Claude’s Code, an analytics website created by software engineer Jodan Alberts.

The Georgia Tech researchers started their measurements on May 1, 2025, and as of March 20, 2026, the CVE scorecard reads

  • 49 for Claude Code (11 critical)
  • 15 for GitHub Copilot (2 critical)
  • 2 for Aether
  • 2 for Google Jules (1 critical)
  • 2 for Devin
  • 2 for Cursor
  • 1 for Atlassian Rovo
  • 1 for Roo Code

That’s 74 CVEs attributable to AI-authored code out of 43,849 advisories analyzed.

Hanqing Zhao, a researcher with the Georgia Tech SSLab, told The Register in an email that those AI CVEs could be viewed as a lower bound and not as a ratio.

“Those 74 cases are confirmed instances where we found clear evidence that AI-generated code contributed to the vulnerability,” he said. “That does not mean the other ~50,000 cases were human-written. It means we could not detect AI involvement in those cases.

“Take OpenClaw as an example. It has more than 300 security advisories and appears to have been heavily vibe-coded, but most AI traces have been stripped away. We can only confidently confirm around 20 cases with clear AI signals. Based on projects like that, we estimate the real number is likely 5 to 10 times higher than what we currently detect.”

Zhao said the CVE count should not be read as a sign that AI code tools deliver more secure code just because it’s low.

“Claude Code alone now appears in more than 4 percent of public commits on GitHub,” he explained. “If AI were truly responsible for only 74 out of 50,000 public vulnerabilities, that would imply AI-generated code is orders of magnitude safer than human-written code. We do not think that is credible.”

The low number, he said, “reflects detection blind spots, not superior AI code quality.”

The Georgia Tech findings amplify research published in November 2024 by Georgetown University’s Center for Security and Emerging Technology.

Based on tests of GPT-3.5-turbo, GPT-4, Code Llama 7B Instruct, WizardCoder 7B, and Mistral 7B Instruct, the Georgetown researchers found, “Across all five models, approximately 48 percent of all generated code snippets were compilable but contained a bug that was flagged by ESBMC [the Efficient SMT-based Context-Bounded Model Checker], which we define as insecure code.”

About 30 percent of the generated code snippets passed ESMBC verification and were deemed secure.

Zhao said the amount of AI-generated code being committed is surging. “End-to-end coding agents are taking off right now,” he explained. “Claude Code alone has over 15 million total commits on GitHub, accounting for more than 4 percent of all public commits.

“Partly that reflects more people using AI tools. But it’s not only volume. The way people use these tools is changing. A year ago most developers used AI for autocomplete. Now people are vibe coding entire projects, shipping code they’ve barely read. That’s a different risk profile.” ®



Source link

Dutch court bans xAI’s Grok from generating nonconsensual nude images | Technology News

0

Court dismissed xAI claim that measures were taken after plaintiff produced video of nude person shortly before hearing.

A Dutch court has ordered Elon Musk’s xAI to stop generating and distributing nude images of people without their consent in the Netherlands, warning it would impose fines of 100,000 euros ($115,350) per day for noncompliance.

The Amsterdam District Court ruled Thursday that xAI’s Grok artificial intelligence tool and the X platform that hosts it were barred from “generating and/or distributing sexual imagery” featuring people “partially or wholly stripped naked without having given their explicit permission”.

Recommended Stories

list of 3 itemsend of list

The decision in a civil suit was one of the first times a judge has weighed in on xAI’s responsibility for creating tools that can be used to create sexualised images, amid a flood of complaints and investigations over Grok in the Americas, Europe, Asia and Australia.

Grok was launched by Musk in 2023 and distributed through his social media platform X, which is now part of his rocket and space exploration company SpaceX.

Offlimits, a Dutch centre monitoring online violence, took legal action in cooperation with the non-profit Victims Support Fund over a Grok feature allowing users to ask it to create hyper-realistic deepfake montages of naked women and children using real photos.

At a hearing this month, xAI lawyers had argued it was impossible to guarantee that abuse on its platform could be prevented, and the company should not be punished for the actions of malicious users.

They said the company had taken measures in January to prevent Grok from editing images of real people in revealing clothing, including restricting its image creation features to paid subscribers.

The court website said the judge had decided that Offlimits had shown there was reasonable doubt over the effectiveness of the measures taken to date. “For example, Offlimits managed to produce a video of a nude person using Grok shortly before the hearing,” it stated.

Offlimits director Robbert Hoving said the “burden is on the company” to make sure its tools are not used to create and distribute nonconsensual sexual images, including of children.

Earlier on Thursday, the European Parliament approved a ban on artificial intelligence systems generating sexualised deepfakes, after global outrage over non-consensual Grok-produced nudes.



Source link

Amarnath Yatra: First puja on 29th June and preparations for the Yatra from 17th July, administrative activities intensified; Brainstorming on the route – Amarnath Yatra: First Puja On June 29; Preparations For The Yatra Begin On July 17.

0

Preparations have been started by the Shrine Board and administrative officials regarding Shri Amarnath Yatra. The first traditional puja is to be held before the yatra on June 29 and the yatra is likely to begin from July 17. However, the official announcement of the dates is expected soon.



The administration has started preparations on a large scale to make the journey smooth and safe. A round of coordination meetings is going on with various agencies regarding security arrangements. Additional surveillance is being planned in sensitive areas falling between the Yatra. Apart from this, health services, disaster management and emergency response mechanisms are also being strengthened.

Repair work on the Yatra route Pahalgam and Baltal has been expedited so that the devotees do not face any kind of problem. Special attention is being given to improving langar sites, drinking water, toilets and accommodation facilities. The number of medical camps and ambulance services is also being increased.

Focus on better management and ensuring safe travel
Every year lakhs of devotees from India and abroad join this holy journey to have the darshan of Baba Barfani. In such a situation, the focus of the administration this time too is on better management and ensuring safe travel. Officials say that all preparations will be completed on time so that the devotees can experience a smooth and safe journey.

Ted Danson admits he can be a ‘d—‘ despite his nice-guy reputation

0

NEWYou can now listen to Fox News articles!

Ted Danson admits he isn’t always the nice guy he portrays himself as.

During a recent episode of his podcast, “Where Everybody Knows Your Name,” the 78-year-old actor admitted to his guest, actor Don Cheadle, that he is a “dick.”

“My go-to is nice guy. My go-to is wanting to be nurturing and loving and kind and all that stuff. It really is,” he said. “But I’m a d–k. I can be a mean a–hole, but I’ve only discovered that later in life because I was trained to be very sensitive.”

Having always thought of himself as a nice guy, Danson was surprised when his wife of more than 30 years, actress Mary Steenburgen, challenged that self-image.

TED DANSON ADMITS FILMING LOVE SCENES WITH STRANGERS MAKES HIM FEEL ‘GUILTY’ AND ‘WRONG’

Ted Danson on stage at the Golden Eve: The Golden Globes Honor Helen Mirren & Sarah Jessica Parker event in Los Angeles in January 2026.

Danson admits he can be mean at times. (Michael Buckner/Penske Media via Getty Images)

“She said, ‘You are as mean as a junkyard dog,’ and it was the first time I’d heard that phrase and I thought it was so silly to be said about me,” he said. “I luckily have grown and developed with my relationship with Mary to realize, ‘Oh yeah, I do have that,’ which is a wonderful thing to know that you are both.”

The actor became a household name when he landed the role of Sam Malone on the hit sitcom, “Cheers,” which won him two Emmy Awards and multiple Golden Globe Awards.

After his run on the show, Danson starred in many successful films, later introducing himself to a younger audience in “The Good Place,” in which he played a demon who developed a conscience and turned good. He is currently starring as a spy in the Netflix series, “Man on the Inside.”

Steenburgen joined the season two cast of the Netflix show as Danson’s character’s love interest. Steenburgen told People in November 2025 that when she found out she had landed the role, “there was a lot of screaming and jumping up and down … because we were so excited to work together.”

LIKE WHAT YOU’RE READING? CLICK HERE FOR MORE ENTERTAINMENT NEWS

Ted Danson and Mary Steenburgen at the Golden Eve: The Golden Globes Honor Helen Mirren & Sarah Jessica Parker event in Los Angeles in January 2026.

The couple star alongside each other in Season 2 of “Man on the Inside.” (Gilbert Flores/Penske Media via Getty Images)

“We’re both actors,” Danson told the outlet. “We were trained the same way. We had some really good material to work with. We’d get up every morning giggling about what we get to do.”

The couple met in 1993 while on set of the movie “Pontiac Moon” and quickly became one of Hollywood’s most-loved couples. They went on to get married in October 1995 in a ceremony on Martha’s Vineyard.

When speaking about their relationship to People in February 2021, Danson explained he knew he had to propose to her because he “couldn’t imagine not being with her at all times.”

CLICK HERE TO SIGN UP FOR THE ENTERTAINMENT NEWSLETTER

“Not to sound corny, but I would sign up for 100 more lifetimes,” Steenburgen told the outlet. “He makes me a better person. He’s a truly beautiful human being. A great big soul. I love how he sees the world and how he cares about people, and he’s deeply hilarious, which is super, super sexy to me and he smells really nice.”

Ted Danson and Mary Steenburgen at the Emmy Awards in Los Angeles in September 2025.

Danson and Steenburgen got married in October 1995. (John Shearer/WireImage)

In addition to starring together in “Pontiac Moon” and “Man on the Inside,” the couple has appeared together on-screen in “Gulliver’s Travels,” “Ink,” “Curb Your Enthusiasm” and other projects.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP



Source link

Key takeaways from Trump’s war on Iran meeting | Donald Trump

0

NewsFeed

US President Donald Trump held a cabinet meeting where he discussed the war on Iran with senior officials. Al Jazeera’s Alan Fisher explains the key takeaways.



Source link

Sarah Michelle Gellar, Elijah Wood and more evacuated in Paris hotel fire

0

NEWYou can now listen to Fox News articles!

Sarah Michelle Gellar, Elijah Wood and more “Ready or Not 2” stars were forced to evacuate from a Paris hotel after a fire broke out on Wednesday. 

Members of the cast — who are currently in Paris promoting their upcoming film — were among 400 guests and service workers of Le Bristol Paris who were evacuated at 11:30 a.m. local time on Wednesday after a fire broke out in the kitchens of the hotel’s 114 Faubourg restaurant, according to TMZ

In a statement to Entertainment Weekly, Le Bristol communications director Fanny Crawford confirmed that the fire has been fully contained and extinguished, and that the hotel’s staff, along with its guests, have safely returned.

SARAH MICHELLE GELLAR ON WHY SHE DITCHED HOLLYWOOD FOR NEARLY A DECADE

Sarah Michelle Gellar, Elijah Wood, Kathryn Wood

Sarah Michelle Gellar, Elijah Wood and Kathryn Newton were among 400 people evacuated from a Paris hotel after a fire broke out.  (Marc Piasecki/WireImage)

The hotel, along with all of its outlets, with the exception of 114 Faubourg, has now reopened,” the statement read.

CLICK HERE TO SIGN UP FOR THE ENTERTAINMENT NEWSLETTER

Additionally, Crawford thanked firefighters and law enforcement “for their prompt intervention and professionalism,” and the impacted guests “for their understanding, calm, and cooperation in response to this situation. The safety of our staff and guests remains our absolute priority. Our teams remain fully mobilized to ensure a return to normal operations under the best possible conditions.”

Kathryn Newton and Sarah Michelle Gellar

Kathryn Newton and Gellar joked about the evacuation in a video circulating online.  (Ernesto Ruscio/Getty Images)

The “Ready or Not” cast was reportedly participating in a press junket when the fire broke out. 

LIKE WHAT YOU’RE READING? CLICK HERE FOR MORE ENTERTAINMENT NEWS

In a video circulating online, the film’s star Kathryn Newton and Gellar seem to joke about escaping a fire mid-junket. 

Sarah Michelle Gellar standing on a red carpet at the Forte Village Resort.

Sarah Michelle Gellar is part of the “Ready or Not 2” cast (Daniele Venturelli /Getty Images)

“The difference between how I escape a fire, and how Kathryn escapes a fire,” Gellar, who was wearing hotel slippers, said. Newton was in full glam, including a pair of high-heels.

 “I never take them off,” Newton joked. 

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Representatives for Gellar, Wood and the Le Bristol Paris did not immediately respond to Fox News Digital’s request for comment. 



Source link

Drunk driver crashes through Florida airport gate onto airfield, police say

0

NEWYou can now listen to Fox News articles!

An intoxicated Florida man is behind bars after allegedly smashing through an airport gate and driving onto the airfield before attempting to enter an occupied airplane, police said. 

Authorities responded to Daytona Beach International Airport around 4:30 p.m. on Wednesday regarding reports of a blue Ford Mustang that drove through a gate at the international terminal of the airport, according to the Volusia County Sheriff’s Office. 

Witnesses reported watching the driver of the Mustang nearly striking a taxiing airplane as it veered down the airfield, officials said. 

FLIGHT ATTENDANT SURVIVES BEING THROWN FROM AIR CANADA FLIGHT IN DEADLY LAGUARDIA CRASH: ‘TOTAL MIRACLE’

Bryan Parker's Florida mugshot

Bryan Parker is charged with aircraft piracy, driving under the influence, two counts of indecent exposure, criminal mischief and burglary of an unoccupied conveyance, after he allegedly rammed through a gate and tried to board three airplanes at Daytona Beach International Airport in Florida on March 25, 2026.  (Volusia County Sheriff’s Office)

The driver, later identified as 58-year-old Bryan Parker, then allegedly exited his vehicle on the airfield and approached an occupied, running plane before attempting to make entry.

When Parker realized the airplane was locked, authorities say he ran to two unoccupied planes and “briefly made entry to them” before being approached by airport staff and Embry-Riddle Aeronautical University security. 

DOT CRACKDOWN PULLS HUNDREDS OF ENGLISH-ILLITERATE, ILLEGAL IMMIGRANT TRUCKERS OFF ROADS AS CRASHES MOUNT

Florida body camera footage showing Bryan Parker's arrest in Volusia County

Bryan Parker was allegedly intoxicated when authorities say he rammed through a gate and tried to board three airplanes at Daytona Beach International Airport in Volusia County, Florida on March 25, 2026. (Volusia County Sheriff’s Office)

An airport operations technician subsequently pulled Parker out of a plane and sat him on his truck’s tailgate, but he jumped off the vehicle and began running toward another plane before he was once again detained.

Body camera video shows the moment Parker reveals to deputies that he is under the influence of alcohol and drugs, causing him to not remember what led up to the incident. 

EXCLUSIVE: CAMERAS CAPTURE TRUCKERS UNABLE TO READ ROAD SIGNS, ANSWER BASIC QUESTIONS DURING FLORIDA CRACKDOWN

Florida body camera footage showing Bryan Parker's arrest in Volusia County

Bryan Parker allegedly was under the influence of alcohol, weed and cocaine when authorities say he rammed through a gate and tried to board three airplanes at Daytona Beach International Airport in Volusia County, Florida on March 25, 2026. (Volusia County Sheriff’s Office)

“I don’t remember, I was at my house,” Parker can be heard telling officers. “I went to an AA meeting and next thing you know, I’m doing cocaine, drinking and smoking pot.”

“So you were doing a lot of drugs and ran through a gate?” the officer asks. 

GOT A TIP?

“Yeah, and I crashed my car,” Parker replies.

FOLLOW US ON X

Parker is then seen sitting on the ground near an active taxiway while in handcuffs, telling officers to, “take me away.” 

GET BREAKING NEWS BY EMAIL

Parker was subsequently taken into custody and charged with aircraft piracy, driving under the influence, two counts of indecent exposure, criminal mischief and burglary of an unoccupied conveyance, according to jail records.

CLICK HERE FOR MORE US NEWS

He is being held without bond in the Volusia County Jail. 

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

The Volusia County Sheriff’s Office did not immediately respond to Fox News Digital’s request for comment. 



Source link

Stefanik presses Michigan president on Chinese student spy security audit

0

NEWYou can now listen to Fox News articles!

Rep. Elise Stefanik, R-N.Y., continued her relentless cross examinations of college administrators Thursday – this time pressing Michigan’s interim president Domenico Grasso on Chinese student spies at the university.

Stefanik wanted to know why Chinese nationals in Michigan were accused of spying on America and his university is not auditing potential national security vulnerabilities in research there.

“Last year, facing congressional pressure, Michigan ended its partnership with Shanghai Jiao Tong University after five Chinese students were caught spying at night and taking illegal photos of U.S. military drills and equipment on the remote Michigan installation Camp Grayling,” Stefanik said. “These students lied and misled U.S. law enforcement about their motives and later conspired on the CCP-controlled messaging app WeChat to clear their phones and cameras of photos and evidence.”

“Has the university conducted a full audit to determine what intellectual property or federally funded research was compromised?” the congresswoman asked.

CHINESE UNIVERSITY OF MICHIGAN STUDENTS CHARGED AFTER ALLEGEDLY SPYING ON MILITARY BASE

Split of Rep. Elise Stefanik and interim University of Michigan president Domenico Grasso

Rep. Elise Stefanik questioned interim University of Michigan president Domenico Grasso during a hearing Thursday, March 26, 2026, on Capitol Hill in Washington, D.C. (C-SPAN)

Without an audit, Grasso responded, “we are unaware of any research that was compromised by these individual students,” noting the alleged spying occurred “miles and miles away from campus.”

But Stefanik was nonplussed by the answer.

“I understand Camp Grayling is off campus, but was there an audit conducted?”

TRUMP DOUBLES DOWN ON PLAN FOR 600,000 CHINESE STUDENT VISAS DESPITE MAGA BACKLASH

Elise Stefanik

Rep. Elise Stefanik, R-N.Y., has made headlines with her questioning U.S. academic leaders, during House Education and the Workforce Committee hearings. (Haiyun Jiang/Bloomberg)

Grasso admitted Michigan did not.

“Well, they were not researchers,” he said, doubting “they did something nefarious.” “They were undergraduate students. So, we did not do an audit.”

And, adding, “they did not have any access to any of our research.”

FOREIGN-BACKED INFLUENCE IN SCHOOLS TO BE EXPOSED UNDER GOP ‘TRACE ACT’ GIVING PARENTS ACCESS TO CURRICULUM

But Stefanik noted they were found to be spying.

“Well, they did do something nefarious off campus,” she said. “I think it would be important for the university to ensure that there is a full audit conducted to make sure that no research, that they didn’t take any nefarious acts there.”

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Grasso admitted he does “not know what all of our researchers are involved in,” but doubted the Department of War would clear them for access to U.S. secrets on campus.

“Congresswoman, we have improved, and we’re continuing to improve our background checks for all of our researchers and students that come into the country, but we also have to partner more closely with our federal intelligence community to make sure that these students are vetted before they’re allowed to get visas to enter our country as well,” he concluded.



Source link

Chicago Loop teen takeover leads to juvenile arrests and curfew order

0

NEWYou can now listen to Fox News articles!

A large teen gathering in downtown Chicago descended into chaos Wednesday night—prompting a curfew enforcement order and intensifying the debate over how to stop repeat takeovers in the Loop.

The activity centered around State and Lake streets, where witnesses described crowds of young people running through the area, climbing on vehicles and engaging in fights.

Alderman Brian Hopkins said conditions escalated quickly before officials intervened.

In a post on X, Hopkins said the situation was “out of control” before a curfew enforcement order was issued around 10 p.m. He said the crowd began to thin out within about 40 minutes, calling the response effective.

SPRING BREAK HOT SPOTS TURN LAWLESS AS FIGHTS ERUPT, DRUGS FLOW AND DOZENS ARRESTED IN SWEEPING CRACKDOWNS

Chicago police confirmed multiple enforcement actions tied to the gathering, including eight juvenile arrests and 24 curfew violations.

According to police, seven juveniles, ranging in age from 13 to 16, were each charged with misdemeanor reckless conduct. One of those teens, a 15-year-old boy, also had an outstanding warrant.

Another 16-year-old boy faces more serious charges, including three felony counts of aggravated assault of a peace officer, along with a misdemeanor reckless conduct charge and a citation for riding a bicycle on the sidewalk.

TEEN MOB STORMS GAS STATION, LONE CLERK SHELLED WITH SNACKS IN CAUGHT-ON-CAM CHAOS

Group of teens gathered in downtown Chicago Loop during chaotic takeover near State and Lake

A large group of teens gathers in Chicago’s Loop near State and Lake streets during a reported “teen takeover,” as crowds fill downtown streets and spark concerns over public safety and curfew enforcement. (Justin/Fox 32 Chicago)

Details about the chaos were also captured by witnesses and groups monitoring activity downtown.

FOX 32 Chicago reported that a private security group, the Community Intelligence Unit, observed multiple fights and said one teen was beaten unconscious. The group also reported that bear mace was used at some point and that several minors were detained.

Social media posts and police scanner traffic added to the sense of disorder, with unverified reports of multiple assaults, fights inside a nearby subway station, and a convenience store being looted. One post also claimed a street vendor was threatened with her own knife. Authorities have not confirmed those accounts.

FOLLOW US ON X

The scene was also described by Justin Peters of ChiTown Crime Chasers, who told FOX 32 Chicago he saw hundreds of teens running through the area.

Teens fighting on sidewalk during chaotic gathering in downtown Chicago Loop

Fights break out among teens during a chaotic gathering in downtown Chicago’s Loop, as witnesses describe hundreds of young people running through the streets, climbing on cars, and clashing with one another. (Justin/Fox 32 Chicago)

“We saw two to three hundred kids running back and forth, jumping on cars, fighting, and taunting police,” Peters told the outlet. He said he and his team also helped a boy who had been beaten unconscious and called for medical assistance.

Peters added that similar incidents have been happening more frequently in recent months, particularly downtown.

GOT A TIP?

City leaders are already debating changes to Chicago’s curfew ordinance in response to repeated large teen gatherings, some of which have turned violent.

GET BREAKING NEWS BY EMAIL

Chicago police arrest individual during teen takeover chaos in downtown Chicago Loop

Chicago police detain an individual during a chaotic teen takeover in the Loop, where officers made multiple arrests and issued curfew violations following reports of violence and disorder. (Justin/Fox 32 Chicago)

A proposed update would allow officers to issue a 30-minute warning for crowds to disperse before taking enforcement action. Police would also be required to ask individuals their age and reason for being out before issuing citations.

CLICK HERE FOR MORE US NEWS

Several aldermen have pushed for stronger measures following past incidents that have resulted in injuries and, in some cases, deadly violence.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

As of now, it remains unclear what prompted Wednesday night’s gathering—or whether new policies will be enough to prevent similar scenes in the future.

Fox News Digital reached out to Mayor Brandon Johnson’s office for comment. 

Stepheny Price covers crime, including missing persons, homicides and migrant crime. Send story tips to stepheny.price@fox.com.



Source link

New Langflow flaw actively exploited to hijack AI workflows

0

CISA: New Langflow flaw actively exploited to hijack AI workflows

The Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are actively exploiting a critical vulnerability identified as CVE-2026-33017, which affects the Langflow framework for building AI agents.

The security issue received a critical score of 9.3 out of 10 and can be leveraged for remote code execution, allowing threat actors to build public flows without authentication.

The agency added the issue to the list of Known Exploited Vulnerabilities, describing it as a code injection vulnerability.

Researchers at application security company Endor Labs claim that hackers started exploiting CVE-2026-33017 on March 19, about 20 hours after the vulnerability advisory became public.

No public proof-of-concept (PoC) exploit code existed at the time, and Endor Labs believes that attackers built exploits directly from the information included in the advisory.

Automated scanning activity began in 20 hours, followed by exploitation using Python scripts in 21 hours, and data (.env and .db files) harvesting in 24 hours.

Langflow is a popular open-source visual framework for building AI workflows with 145,000 stars on GitHub. It provides a drag-and-drop interface for connecting nodes into executable pipelines, along with a REST API for running them programmatically.

The tool has widespread adoption across the AI development ecosystem, making it an attractive target for hackers.

In May 2025, CISA issued another warning about active exploitation in Langflow, targeting CVE-2025-3248, a critical API endpoint flaw that allows unauthenticated RCE and potentially leads to full server control.

The most recent flaw, CVE-2026-33017, lets attackers execute arbitrary Python code impacts versions 1.8.1 and earlier of Langflow, and could be exploited via a single crafted HTTP request due to unsandboxed flow execution.

CISA did not mark the flaw as exploited by ransomware actors, but gave federal agencies until April 8 to apply the security updates or mitigations, or stop using the product.

System administrators are recommended to upgrade to Langflow version 1.9.0 or later, which addresses the security problem, or disable/restrict the vulnerable endpoint.

Endor Labs also advised not to expose Langflow directly to the internet, to monitor outbound traffic, and to rotate API keys, database credentials, and cloud secrets when suspicious activity is detected.

CISA’s deadline formally applies to organizations covered by Binding Operational Directive (BOD) 22-01, but private sector companies, state and local governments, and other non-FCEB entities are also advised to treat it as a benchmark and respond accordingly.

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.



Source link