/Vulnerability Library

Langflow < 1.9.0 - Remote Code Execution

CVE-2026-33017
Verified

Description

Langflow versions prior to 1.9.0 are vulnerable to unauthenticated remote code execution (RCE) via the build_public_tmp endpoint. Attackers can submit a manipulated flow JSON containing Python code that is executed during the build process without proper sandboxing.

Severity

Critical

CVSS Score

9.8

Exploit Probability

25%

Affected Product

langflow

Published Date

March 24, 2026

Template Author

himind

CVE-2026-33017.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2026-33017
CWE ID:
cwe-94

References

https://thehackernews.com/2026/03/critical-langflow-flaw-cve-2026-33017.htmlhttps://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hourshttps://nvd.nist.gov/vuln/detail/CVE-2026-33017

Remediation Steps

Update to version 1.9.0 or later.