Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-33017
langflow-ai langflow — Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 9.3 .2475 97.8 YES
AFFECTED
Product Versions Fixed
langflow < 1.9.0 – —
TIMELINE
Mar 17 Reserved by GitHub_M
Mar 20 Published (CNA: GitHub_M)
Mar 25 Added to CISA KEV, remediation due 2026-04-08
Description
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| March 17, 2026 | Reserved | Reserved by GitHub_M |
| March 20, 2026 | Published | Published (CNA: GitHub_M) |
| March 25, 2026 | KEV ADDED | Added to CISA KEV, remediation due 2026-04-08 |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| langflow-ai | langflow | — | < 1.9.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-33017 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.