Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    CISOs brace for an “AI vs. AI” fight

    October 16, 2025

    How emerging Mubadala-backed AAF is winning VC deals in some of the hottest startups

    October 16, 2025

    Why the F5 Hack Created an ‘Imminent Threat’ for Thousands of Networks

    October 16, 2025
    Facebook X (Twitter) Instagram
    Trending
    • CISOs brace for an “AI vs. AI” fight
    • How emerging Mubadala-backed AAF is winning VC deals in some of the hottest startups
    • Why the F5 Hack Created an ‘Imminent Threat’ for Thousands of Networks
    • Last 48 hours to save before the Disrupt 2025 flash sale ends
    • Is a $300 Windows laptop worth buying? This Acer model gave me a resounding yes
    • How a headphone site operator built loyalty startup Lantern to solve his own problems
    • North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts
    • Rent a Cyber Friend will pay you to talk to strangers online and will show off its platform at TechCrunch Disrupt 2025
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»Critical flaw in AI agent dev tool Langflow under active exploitation
    Security

    Critical flaw in AI agent dev tool Langflow under active exploitation

    TechurzBy TechurzMay 6, 2025No Comments1 Min Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Admin in data center updating systems, protecting hardware equipment from damaging software vulnerabilities. Colleagues looking for bugs causing infrastructure to slow down
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Missing authentication on dangerous API endpoint

    The flaw is rather straightforward and stems from the fact that one API endpoint called /api/v1/validate/code had missing authentication checks and passed code to the Python exec function. However, it didn’t run exec directly on functions, but on function definitions, which make functions available for execution but don’t execute their code.

    Because of this, the Horizon3.ai researchers had to come up with an alternative exploitation method leveraging a Python feature called decorators, which “are functions that return functions that wrap other functions.”

    The proof-of-concept published by Horizon3.ai on April 9 leverages decorators to achieve remote code execution, but the researchers note that a third-party researcher also achieved the same by abusing another feature of Python functions called default arguments.

    active agent Critical dev exploitation flaw Langflow Tool
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleMeet the New Surface Copilot+ PCs: Lightweight, AI-Ready, $799
    Next Article Vote for T3’s Readers’ Choice Award and tell us your best product of 2025
    Techurz
    • Website

    Related Posts

    Security

    CISOs brace for an “AI vs. AI” fight

    October 16, 2025
    Security

    Why the F5 Hack Created an ‘Imminent Threat’ for Thousands of Networks

    October 16, 2025
    Security

    Is a $300 Windows laptop worth buying? This Acer model gave me a resounding yes

    October 16, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    The Reason Murderbot’s Tone Feels Off

    May 14, 20259 Views

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    CNET’s Daily Tariff Price Tracker: I’m Keeping Tabs on Changes as Trump’s Trade Policies Shift

    May 27, 20258 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    The Reason Murderbot’s Tone Feels Off

    May 14, 20259 Views

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    CNET’s Daily Tariff Price Tracker: I’m Keeping Tabs on Changes as Trump’s Trade Policies Shift

    May 27, 20258 Views
    Our Picks

    CISOs brace for an “AI vs. AI” fight

    October 16, 2025

    How emerging Mubadala-backed AAF is winning VC deals in some of the hottest startups

    October 16, 2025

    Why the F5 Hack Created an ‘Imminent Threat’ for Thousands of Networks

    October 16, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.