CVE-2026-33017
Published Mar 20, 2026
Last updated 4 days ago
- Description
- Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.
- Source
- security-advisories@github.com
- NVD status
- Modified
- Products
- langflow
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Langflow Code Injection Vulnerability
- Exploit added on
- Mar 25, 2026
- Exploit action due
- Apr 8, 2026
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- security-advisories@github.com
- CWE-94
- Hype score
- Not currently trending
openai dropped CVE-2026-33017. unauth RCE, CVSS high, exploit available. if you have openai in your stack, block external access to the affected endpoint until patched. #OpenAI #RCE #GitHub #CVE-2026-33017 https://t.co/BIbf7f8WjV
@trerbbb
18 May 2026
93 Impressions
2 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Langflow CVE-2026-33017 Exploited to Steal AWS Keys, Deploy NATS Worker https://t.co/6k29gf4M4k
@PVynckier
17 May 2026
128 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
breaking: microsoft's copilot faces 2025's echoleak (cve-32711), a critical zero-click vuln. servicenow virtual agent is hit by bodysnatcher (cve-2025-12420). langflow's cve-2026-33017 is critical. your ai agents are high-value targets. audit and patch your systems now. https://t
@The_Agent_Econ
29 Mar 2026
130 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Langflow just got its second CISA KEV in two years. CVE-2026-33017. Same exec() architecture as CVE-2025-3248. Attackers went from advisory to credential harvesting in 24 hours - no PoC required. This is not a patch problem. It is an architecture problem that was never fixed.
@jlabernathy
28 Mar 2026
121 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
I found CVE-2026-33017, a Critical 9.3 unauthenticated RCE in Langflow, by looking at the code path the previous CISA KEV fix (CVE-2025-3248) missed. - https://t.co/gFBy4aiRQe #aisecurity #langflowvulnerability
@hackernoon
26 Mar 2026
338 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B38E7511-B77D-4E5F-B33A-458EE5770358",
"versionEndExcluding": "1.8.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]