Monero Miner Takes Advantage of a Langflow RCE Exploit

A Langflow vulnerability exposed since March 2026 continues to be exploited by threat actors, this time to deploy Monero cryptocurrency miners into a system. The vulnerability involves a single line of Python that can be entered into a Langflow API endpoint. Since the endpoint is improperly authenticated, malicious users can easily inject miner binaries into a system, launching executables that harness large amounts of CPU or GPU power to mine Monero. Additionally, the malware makes certain file directories immutable, meaning they cannot be easily changed or removed, even by an admin. These combinations of effects make it highly likely that a device could be infected with a miner for extended periods of device, leading to serious overheating and hardware failure on the user side.