The scaffolding half the industry builds AI agents on made the US cybersecurity list with a hole that has no lock.
LangChain is the work of Harrison Chase, who a few years ago wrote the first version as a side project - 800 lines of Python code. The idea is simple: everyone who connects a language model (ChatGPT-type software that understands and writes text) to a database, to memory of a past conversation, or to some tool solves the same problem all over again. Chase solved it once and released it open for everyone to use. In three years the project reached a valuation of 1.25 billion dollars and over 100 million downloads a month - LangChain became the scaffold half the industry builds its agents on.
Langflow is the next step - the same scaffold, but with a drag-and-drop interface instead of writing code. The goal is to let even people who don't program assemble agents visually - an arrow from 'model' to 'database', an arrow from 'database' to 'result'. The speed with which someone with no technical background assembles a working agent in an hour is exactly why Langflow spread quickly through companies racing not to fall behind.
And that same speed is what bred the hole. The vulnerability CVE-2025-34291 scored 9.4 out of a maximum ten on the danger scale - a combination of three gaps at once: the server trusts requests from almost any address, there's no protection against forged requests made in someone else's name, and by design there's an input that executable code passes through. Put together, the three holes give an attacker full access without a single identity check.
An Iranian state hacking group nicknamed MuddyWater is already using it - not as a demonstration, but as a real way into other people's networks. CISA, the federal agency that protects US infrastructure, added the hole to its catalog with a mandatory deadline - government institutions had to patch it by early June. The scaffold built to speed up building agents turned out to be the scaffold attackers climbed into the buildings through.
Who profits from this
I know the temptation from the inside - when you're building a system, the easiest path is to take a ready-made scaffold and hang yours on it. It's faster, it's cheaper, it works right away in front of the client. But the scaffold isn't yours. You haven't checked every beam, you don't know who else climbs up it at night.
That's why our rule is that the system is closed by default - nobody from outside gets in unless explicitly allowed. Langflow proved with numbers what the opposite costs: convenience without a boundary is paid for with a door that has no lock. The question is never whether they'll find the gap. The question is who gets there first.