🔴 LIVE — Updated every 10 minutes
👤 -- reading now 🌡 Nairobi
Breaking
HomeTechnology7,000 Langflow servers are under attack.…
Technology

7,000 Langflow servers are under attack. LangGraph and LangChain have the same holes

VentureBeat Jun 19, 2026 Jun 19 ⏱ 1 min read 👁 19 views
7,000 Langflow servers are under attack. LangGraph and LangChain have the same holes
Image via VentureBeat
📋 Article Summary
208 words
Your AI agent did exactly what it was designed to do. The framework underneath it just handed an attacker a shell on the box that holds your OpenAI key, your database credentials, and your CRM tokens.That is not a hypothetical.… Your AI agent did exactly what it was designed to do. The framework underneath it just handed an attacker a shell on the box that holds your OpenAI key, your database credentials, and your CRM tokens.That is not a hypothetical. In a few months, three of the most widely deployed AI agent frameworks each turned a known, ordinary bug class into a way through. Check Point Research chained a SQL injection in LangGraph’s SQLite checkpointer to full remote code execution. Tenable and VulnCheck tracked a path traversal in Langflow’s file upload endpoint to active, in-the-wild RCE. Cyera documented a path traversal in LangChain-core’s prompt loader that reads your secrets off disk. Two paths to a shell, one to your keys. They are the same bug, wearing three frameworks.These frameworks became production infrastructure faster than anyone secured them. They store agent state, take file uploads, load prompt configs, and hold the credentials to databases, CRMs, and internal APIs. The edge tools…
Continue Reading
Full story on VentureBeat
Read Full Story →
🔗 Clicking will take you to venturebeat.com
Share this story: WhatsApp X/Twitter Facebook
👁 People Also Read
Telegram ban in India sparks a rush to VPNs, rival apps
Technology

Telegram ban in India sparks a rush to VPNs, rival apps

Telegram argues India should block specific content, not an entire platform used by millions.

Read
Aura’s impressive e-ink photo frame doesn’t even look digital
Technology

Aura’s impressive e-ink photo frame doesn’t even look digital

What’s the most cliche possible gift you can give a relative? A digital photo frame, displaying a rotating slideshow of…

Read
Go eyes robotaxis and acquisitions after Japan’s biggest IPO of 2026. Here’s why it matters
Technology

Go eyes robotaxis and acquisitions after Japan’s biggest IPO of 2026. Here’s why it matters

Go’s IPO — Japan’s biggest so far this year — has done more than provide a much-needed boost to the…

Read
Top South Africa tech investor says it is no longer just a Tencent story
Technology

Top South Africa tech investor says it is no longer just a Tencent story

While Tencent consistently delivered outsized returns, many of Prosus's businesses remained focused on growth rather than profitability.

Read