A critical security vulnerability in Langflow, the popular open-source LLM builder, is being actively exploited in the wild — with threat actors siphoning OpenAI API keys and AWS credentials from multiple Indian enterprises. The flaw, now added to CISA's Known Exploited Vulnerabilities (KEV) catalog as the first AI agent platform to make the list, carries a Thursday deadline for federal agencies to patch. Security researchers warn that unpatched Langflow instances are leaking sensitive cloud credentials that power AI workflows.
- Core Update: A critical Langflow flaw is actively exploited to steal OpenAI, AWS, and Azure keys from Indian companies using the platform for agentic AI builds.
- Key Metrics / Specs: CISA added the platform to its KEV list — a first for any AI agent framework — and issued a Thursday patch deadline across four CVEs.
- Access & Availability: Immediate mitigation requires upgrading Langflow to the latest patched release, rotating all exposed API keys, and auditing cloud permissions.