Langflow < 1.7.0 - Path Traversal
CVE-2026-33497
Verified
Description
Langflow < 1.7.1 contains a path traversal caused by insufficient filtering of folder_name and file_name parameters in download_profile_picture endpoint, letting attackers read secret_key across directories, exploit requires crafted request.
Severity
High
CVSS Score
7.5
Exploit Probability
2%
Published Date
July 13, 2026
Template Author
xtr0nix
CVE-2026-33497.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-33497
CWE ID:
cwe-22
Remediation Steps
Update to version 1.7.1 or later.