Hacking your life with AI can get you hacked
Blog post from Endor Labs
Security research presented at DEF CON 34 examined seven widely used AI workflow and orchestration platforms—NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, and Apache Airflow—and reported fourteen high- and critical-severity vulnerabilities involving remote code execution, command injection, sandbox bypasses, SQL injection, and unauthenticated execution paths. The findings argue that these products often treat workflow authors and trigger users as trusted despite functioning as multi-tenant code-execution environments connected to sensitive credentials, enterprise data, email, calendars, and other agent context. Reported issues included broken or disabled sandbox protections in NocoBase, LLM-generated code passed to evaluators in Flowise and Langflow, security controls applied only after attacker-controlled code ran in Dify and Activepieces, and webhook or templating paths that could execute commands in Kestra and Airflow. Several vendors issued fixes or advisories, while others characterized the behavior as intended and recommended deployment hardening, least-privilege permissions, and isolated task runners; Airflow’s reported fix was documentation-only, and Flowise was described as archived and no longer maintained. The research recommends treating exposed workflow triggers as code-execution endpoints, adding authentication and reverse-proxy protections, restricting workflow and trigger permissions, disabling risky defaults, auditing existing workflows, upgrading patched deployments, and migrating away from unmaintained software.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| LLM | 7 | 5,068 | 1,020 | 229 | -34% |
| AI Agents | 3 | 5,780 | 1,243 | 245 | -15% |
| Serverless | 3 | 783 | 217 | 99 | +1% |
| Kubernetes | 1 | 3,490 | 385 | 112 | +26% |
| MCP | 1 | 8,729 | 854 | 211 | -20% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.