CVE-2026-33017
Langflow Code Injection Vulnerability
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog: attackers are using it. If you run Langflow, fix it now.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
US federal civilian agencies must remediate by Apr 8, 2026.
Patch status
Official fix available since
Apply the vendor's update to every affected system. Check the fixed-in versions below where known.
Basis: NVD patch reference
Description
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
Affected products
| Product | Vendor | Affected versions | Fixed in | Source |
|---|---|---|---|---|
| Langflow | Langflow | < 1.8.2 | 1.8.2 | KEV |
Sources: KEV = CISA Known Exploited Vulnerabilities catalog.
Intelligence timeline
Developments from the last 30 days, newest first.
No developments recorded for CVE-2026-33017 in the last 30 days.
1 earlier event is available with a subscription. See plans.
Coverage
We have not published a story about this vulnerability yet.
