CVE-2026-33017 – Critical Unauthenticated Remote Code Execution in Langflow

TL;DR

  • Critical remote code execution (RCE) in Langflow (CVSS 9.8).
  • Unauthenticated attacker can send malicious Python to POST /api/v1/build_public_tmp/{flow_id}/flow.
  • Active exploitation observed within 20 hours of public disclosure; now listed in CISA KEV.
  • Immediate patch to Langflow 1.9.0 or block the vulnerable endpoint.
  • Monitor for suspicious POST requests and post‑exploit artifacts.

Overview

On 2026‑03‑20, the security community disclosed CVE-2026-33017, a Critical remote code execution flaw in Langflow, an open‑source platform for building AI‑powered agents and workflows. The vulnerability receives a CVSS 9.8 (3.1) (vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CVSS 9.3 (4.0) (vector AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L). The vulnerability has seen active exploitation within 20 hours of disclosure, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to the Known Exploited Vulnerabilities (KEV) catalog on 2026‑03‑25.


Technical Details

  • Vulnerable endpoint: POST /api/v1/build_public_tmp/{flow_id}/flow
  • Root cause: The endpoint is intended for publishing public flows without authentication, but it accepts an optional data parameter containing the full flow definition. When supplied, the server replaces the stored flow data with the attacker‑controlled payload and passes the node definitions directly to Python’s built‑in exec() function.
  • Impact: Because exec() runs with the privileges of the Langflow service, an unauthenticated attacker can execute arbitrary Python code on the host, leading to full system compromise, credential theft, file exfiltration, and lateral movement.
  • CWE classifications: CWE‑94 (Improper Control of Generation of Code), CWE‑95 (Eval Injection), and CWE‑306 (Missing Authentication for Critical Function).

The flaw is distinct from the earlier CVE‑2025‑3248 fix, which added authentication to a different endpoint (/api/v1/validate/code). The vulnerable code path was introduced in early development builds (dev0‑dev11) and persisted in all releases prior to Langflow 1.9.0.


Severity & Impact

MetricValue
SeverityCritical
CVSS 3.19.8 – AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 4.09.3 – AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Attack VectorNetwork (remote)
Privileges RequiredNone
User InteractionNone
ImpactFull system takeover (code execution, data theft, persistence)

Affected Products

All versions of Langflow prior to 1.9.0 are vulnerable. This includes the development releases dev0 through dev11 and any production builds that have not been upgraded to the 1.9.0 release line.

For the complete list of affected CPE entries and version ranges, see the official CVE page: https://vulnsocial.com/cve/CVE-2026-33017.


What Security Teams Should Do

  • Upgrade immediately to Langflow 1.9.0 or later. The fix removes the unsafe exec() call and enforces authentication on the endpoint.
  • Block the endpoint if upgrading is not feasible: configure a web‑application firewall (WAF) or reverse‑proxy rule to deny POST requests to /api/v1/build_public_tmp/*.
  • Audit logs for any POST /api/v1/build_public_tmp activity since 2026‑03‑20. Look for unusual flow_id values, large request bodies, or Python code snippets (import os, subprocess, eval).
  • Detect post‑exploitation artifacts: monitor for new processes spawned by the Langflow service, unexpected files in the working directory, or outbound connections to unknown hosts.
  • Rotate credentials for any services that the compromised Langflow instance could access (cloud APIs, database passwords, secret stores).
  • Apply CISA KEV guidance: follow the recommended mitigation steps outlined in the CISA catalog entry and consider the BOD 22‑01 guidance for cloud‑based services.
  • Track live activity on the vulnerability via the VulnSocial intelligence page: https://vulnsocial.com/cve/CVE-2026-33017.

Remediation & Mitigation

  1. Patch the application by upgrading to Langflow 1.9.0 (or any later release). The commit that fixes the issue is available at https://github.com/langflow-ai/langflow/commit/73b6612e3ef25fdae0a752d75b0fabd47328d4f0.
  2. If an immediate patch is not possible, enforce authentication on the build_public_tmp endpoint via a reverse‑proxy or API gateway.
  3. Deploy a WAF rule that blocks POST requests containing the string exec( or typical Python import statements (import os, subprocess).
  4. Conduct a forensic scan of any host that ran a vulnerable Langflow instance: look for newly created files, scheduled tasks, or suspicious cron jobs.
  5. Rotate all secrets that the compromised service could have accessed and invalidate any tokens that may have been exfiltrated.
  6. Review CISA’s KEV entry for additional mitigation recommendations and ensure compliance with BOD 22‑01 for cloud services.

References


Bottom Line

CVE-2026-33017 is a Critical unauthenticated RCE in Langflow that has been actively exploited within hours of disclosure and is now listed in the CISA KEV catalog. The only reliable mitigation is to upgrade to version 1.9.0 or later and to block the vulnerable endpoint while monitoring for signs of compromise.

#CVE202633017 #CVE #Critical #RCE #CISAKEV #Langflow #AI #Security