boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-33017

langflow-ai langflow — Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .2475   97.8   YES
AFFECTED
  Product   Versions   Fixed
  langflow  < 1.9.0 –  —
TIMELINE
  Mar 17  Reserved by GitHub_M
  Mar 20  Published (CNA: GitHub_M)
  Mar 25  Added to CISA KEV, remediation due 2026-04-08
CWE-94, CWE-95, CWE-306 · CNA: GitHub_M · CVSS v4.0 · 7 references · KEV due April 8, 2026

Description

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
March 17, 2026ReservedReserved by GitHub_M
March 20, 2026PublishedPublished (CNA: GitHub_M)
March 25, 2026KEV ADDEDAdded to CISA KEV, remediation due 2026-04-08

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
langflow-ailangflow—< 1.9.0—

Weaknesses

CWE-94 · CWE-95 · CWE-306

References (7)

Related

Authoritative record: CVE-2026-33017 at cve.org

Vendors: langflow-ai

Weaknesses: CWE-94 · CWE-95 · CWE-306

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-33017 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.