Safely manage your Zendesk from the AI assistant you already use, via the Deltastring MCP. Beacon configuration platform
← Back to news

7,000 Langflow servers are under attack. LangGraph and LangChain have the same holes

Langflow, LangGraph, and LangChain—three foundational frameworks for deploying AI agents—share critical vulnerabilities that have exposed approximately 7,000 Langflow servers to active exploitation. These flaws allow attackers to execute arbitrary code on servers running these frameworks, granting direct access to stored credentials including OpenAI API keys, database passwords, and CRM authentication tokens. The vulnerability is not theoretical; it represents a systemic weakness across the entire stack of tools that organisations are rapidly deploying to automate customer interactions and backend processes. For CX teams already running AI agents through these frameworks—whether for chatbots, ticket routing, or knowledge base integration—the implication is stark: an attacker gaining shell access to your agent infrastructure gains simultaneous access to your customer data, your payment systems, and your integration layer with platforms like Salesforce and Zendesk.

The broader concern extends beyond individual breaches. These frameworks are designed to be composable and widely adopted, meaning a single vulnerability cascades across thousands of deployments simultaneously. This differs fundamentally from isolated vendor breaches; it's an architectural flaw affecting the foundation layer. CX leaders implementing AI agents face a difficult question: how do you isolate agent infrastructure from credential storage when the frameworks themselves were built to centralise access for operational convenience? The related pattern of OAuth compromises and Salesforce data theft attacks suggests attackers are systematically targeting the integration points where CX platforms connect to broader business systems—and AI agent frameworks have become a new, poorly-secured entry point into that ecosystem.

Remediation requires immediate action on two fronts. First, organisations must audit which frameworks power their deployed agents and apply patches immediately; second, they must rotate all credentials that could have been exposed through compromised servers. For teams already managing complex CX stacks across multiple platforms, this represents a significant operational burden, but the alternative—leaving agent infrastructure unpatched—means accepting that customer data and system access remain compromised. The vulnerability underscores a critical gap in how rapidly-adopted AI tooling is being secured relative to how quickly it's being deployed into production environments.