CVE-2026-33017 is a critical unauthenticated remote code execution (RCE) vulnerability affecting Langflow versions prior to 1.9.0. It allows attackers to inject and execute arbitrary Python code via the /api/v1/build_public_tmp endpoint by supplying malicious flow data. Rated 9.8 CRITICAL, this flaw enables full system compromise with low attack complexity over the network, requiring no authentication or user interaction. This vulnerability is actively exploited in the wild, has been added to CISA's Known Exploited Vulnerabilities catalog, and has garnered significant community and media attention due to its rapid exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.2CPE matchmatch criteria | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Langflow Remote Code Execution (CVE-2026-33017)
Mar 23, 2026Langflow Remote Code Execution (CVE-2026-33017)
Mar 23, 2026Langflow Remote Code Execution (CVE-2026-33017)
Mar 23, 2026Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
Mar 17, 2026