logo

AI Workflows Under Fire: Critical RCE and File Write Flaws Expose Langflow Servers

ID: 726bb390-d051-50ee-a99e-f590a45a33a9

STIX ID: report--726bb390-d051-50ee-a99e-f590a45a33a9

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-03-19

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers disclosed two critical vulnerabilities in Langflow (≤1.8.1): CVE-2026-33017, an unauthenticated RCE in the public flow build endpoint that executes attacker-supplied code via Python exec(), and CVE-2026-33309, an authenticated arbitrary file write via multipart filename path traversal. Both allow full server compromise (file read/write, credential theft, persistent RCE) and no official patch was available at the time of the report; immediate mitigations are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.