Multiple Langflow vulnerabilities, including unauthenticated RCE, fixed in 1.9.0
A batch of CVEs disclosed in March 2026 affects Langflow, an AI agent and workflow builder, headlined by CVE-2026-33017, an unauthenticated remote code execution flaw in the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint that passes attacker-supplied node code to exec() without sandboxing. Related issues include arbitrary file write leading to RCE, code execution via the Agentic Assistant's validation phase, cross-tenant flow and image access, path traversal exposing the secret key, and CI shell injection; most are patched in version 1.9.0.
Disclosed 20 March 2026 · Record updated 13 September 2026
Impact
Unauthenticated attackers could execute arbitrary Python code on Langflow servers; authenticated users could read, modify or delete other tenants' flows (including embedded plaintext API keys) and download other users' uploaded images, while CI workflow injection could expose GITHUB_TOKEN and enable supply chain tampering. A referenced vendor blog describes attackers compromising Langflow AI pipelines within 20 hours.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33017
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33053
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33309
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33475
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33484
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33497
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33873
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-34046
