BEST SERVER-SIDE / CLOUD BUG · for CVE-2026-33017 · announced at DEF CON 34, Las Vegas
The Pwnies are the closest thing offensive security has to an industry ballot — the bugs your peers thought were the best work of the year. CVE-2026-33017 was nominated for Best Server-Side / Cloud Bug in 2026. It didn't take the statue at DEF CON 34. The nomination is the part I keep.
|
An unauthenticated |
Langflow sits underneath the AI stack — it holds model credentials, vector-store keys, and tool-call permissions. Compromising the orchestrator compromises everything it orchestrates. CVSS 9.3 CRITICAL. |
Added to the CISA KEV catalog. Exploited in the wild within 20 hours of disclosure. Covered by The Hacker News, Help Net Security, Infosecurity, Sysdig, and Qualys — quoted by name as the discoverer. |
Writeups: Medium · HackerNoon · Advisory GHSA-vwmf-pq79-vjvx · NVD
Four CVEs across two orchestrators, all landing on the same seam: the gap between "we validated this input" and "we already ran it."
| CVE | Target | Finding | Severity | Advisory · Fix |
|---|---|---|---|---|
| CVE-2026-69258 | Flowise | Unauthenticated property injection — the Prediction API spreads overrideConfig into the flow execution context with no allow-list, so an attacker controls internals the flow assumed were server-owned |
8.8 HIGH CVSS 4.0CWE-639 · CWE-915 |
GHSA-6vh2-wg4h-4vwj fixed in flowise@3.1.3 |
| CVE-2026-73081 | Activepieces | OS command injection — the worker builds a Code step's on-disk path from the step name and hands it to a shell-invoked build command. Shell metacharacters execute during compilation, before any sandbox exists | 8.7 HIGH CVSS 4.0CWE-78 |
GHSA-3pfv-m69p-5fv5 fixed in 0.80.0 |
| CVE-2026-73083 | Activepieces | Sandbox escape — in SANDBOX_CODE_ONLY mode the engine loads the compiled module via importFresh() (a require() wrapper) before the V8 isolate is applied. Top-level code reaches child_process, fs, and AP_ENCRYPTION_KEY |
7.6 HIGH CVSS 4.0CWE-693 |
GHSA-gr3h-c2j7-r52g fixed in 0.80.0 |
| CVE-2026-73084 | Activepieces | XSS in the OAuth callback — /api/redirect embeds the attacker-supplied code parameter into an inline <script> unescaped. Unauthenticated script execution in the app origin against any logged-in victim |
6.1 MEDIUM CVSS 3.1CWE-79 |
GHSA-hc39-cm5m-q8g7 fixed in 0.83.0 |
All four assigned via the GitHub CNA. Flowise writeup: Flowise patched overrideConfig. I found the two places the patch never reached.
|
|
A 32-bit integer truncation in vLLM's GGUF dequantization kernels. The kernel processes fewer elements than it allocated, so the tail of the output tensor is never written — it just keeps whatever was in GPU memory before. On a multi-tenant inference server, that residue is another user's data. Nothing crashes. No sanitizer fires. Every individual line of the kernel looks correct, and the types are all perfectly reasonable. It fails silently, which is exactly why it survived from
Writeups: Medium · HackerNoon |
◈ LIVE — htb-sync.yml re-reads the Hack The Box API every six hours and redraws this card whenever a number moves. Last change 2026-10-04 05:51 UTC.
AviralxRoot — Guru on points, Prodigy III · level 89 on XP. Global #65, 1,872 points, 72 user and 53 root flags, 254 challenges, 148 Sherlock tasks, and 6 fortresses cleared end to end. Nothing on this card is typed by hand.
Valid, reproducible findings where the vendor declined assignment (often behind a retroactive documentation shield). Published anyway.
| Target | Finding | Severity | Status |
|---|---|---|---|
XGBoost ×5 |
Heap OOB in tree node access · UBJSON parser memory corruption · Parallel tree double-free · Unsafe pickle.loads() on network data (CWE-502) · Hardcoded 0xff99 magic as Rabit tracker auth (CWE-798) |
CRITICAL / HIGH |
Vendor declined — "performance + resourcing". Full writeup on Medium |
Google sentencepiece |
Off-by-4 bounds check in DecodePrecompiledCharsMap → OOB read via crafted .model (UBSan-confirmed) |
MEDIUM |
Google VRP #498463886 — tokenizer backbone of Gemma, T5, PaLM |
Google sentencepiece |
Unvalidated trie values used as piece-array indices → heap OOB read in release builds | HIGH |
Google VRP #498465599 — upstream fix PR #1207 |
| vLLM | LoRA adapter SSRF → RCE chain | HIGH |
Closed via documentation shield. Public writeup |
Separate from the seven assigned CVEs above.
| Body | Contribution | Detail |
|---|---|---|
| NIST | OLIR Catalog Mapping — live | First AI-security framework mapping in the NIST Online Informative References catalog: OWASP LLM Top 10 v2.0 → NIST CSF 2.0, with 169 relationship entries covering 77 of 106 CSF subcategories. Listed Point of Contact on the NIST CSRC website. |
| MITRE | CWE / CAPEC submissions | Weakness submissions in Phase-03 review, derived from CVE-2026-33017 (AI workflow definition injection). |
Full speaker profile → sessionize.com/aviral-srivastava
| Year | Conference | Talk |
|---|---|---|
2026 |
BSides Las Vegas | Rejected-Input Programming: Exploiting Parsers That Say No Too Late — Breaking Ground, Aug 5 |
2026 |
RSAC 2026 | From Prompt to Pager: Preparing for AI-Native Incidents Now |
2026 |
ISACA North America | Breaking the Loop: Offensive Testing of RL and Agentic AI Systems |
2025 |
CactusCon 14 | Agents Under Siege: Live Attacks from RAG to Tool Calls |
2025 |
CypherCon 2025 | Deceiving the Deceivers: Offensive Security Strategies for Adversarial AI |
2025 |
BSidesSLC | Filling Gaps in AI Governance: How ISO/IEC 42001 Shapes AI Risk & Compliance |
2025 |
BSidesTC | ROP Alchemy: Universal Gadgets via Type Confusion |
2025 |
CactusCon 13 | Weaponizing AI: Adversarial Attacks, Hallucinations, and the Offensive Frontier |
2024 |
HOPE XV | Invited talk — details under NDA |
2024 |
BSidesChicago | Hacking Neural Networks: The Hidden Vulnerabilities of AI Systems |
▶ SIGNAL INTERCEPT — Press coverage of CVE-2026-33017
Quoted by name as the discoverer across major security press. This is the bug that went on to be nominated for a Pwnie.
- The Hacker News — Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure
- Help Net Security — CISA sounds alarm on Langflow RCE after rapid exploitation
- Infosecurity Magazine — Hackers Exploit Critical Langflow Bug in Just 20 Hours
- Sysdig Threat Research — How attackers compromised Langflow AI pipelines in 20 hours
- Cloud Security Alliance — Research Notes ×2
- Qualys ThreatProtect — CISA Added Langflow Vulnerability to KEV Catalog
- Barrack AI — Langflow Got Hacked Twice Through the Same exec() Call
- HackerNoon — CVE-2026-33017: Unauthenticated RCE in Langflow's Public Flow Endpoint Explained
- InfoSec Today · CiberSafety
|
Full-spectrum adversary emulation and exploit automation framework. |
Apple-silicon toolchain (radare2 · lldb · Ghidra headless) running
|
|
Agent team — Recon · Auditor · Exploiter · Reporter — governed by a 14-rule submission framework and a 4-gate filter (unauthenticated · default config · no doc shield · core feature). |
Automated cryptographic challenge generation. MS thesis, Penn State. |
|
Security Engineer (L4) — Amazon Ads Security Sunnyvale, CA · 2025 – Present AppSec reviews · threat modeling · penetration testing · AI/ML security · agentic workflows · prompt injection · RAG hardening Security Internships Teaching Assistant — Red Teaming & CTFs The Pennsylvania State University |
MS, Cybersecurity Analytics & Operations The Pennsylvania State University · GPA 4.0 Research Assistant · RSA Security Scholar Thesis: AI-Generated Cryptographic CTF Challenges BTech, Computer Science — Amity University Cryptography · Secure Systems · Network Security |
