CVE-2026-33309Disclosure(langflow / langflow)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch langflow langflow systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68478 (External Control of File Name), leading to the root architectural issue within `LocalStorageService` remaining unresolved. Because the underlying storage layer lacks boundary containment checks, the system relies entirely on the HTTP-layer `ValidatedFileName` dependency. This defense-in-depth failure leaves the `POST /api/v2/files/` endpoint vulnerable to Arbitrary File Write. The multipart upload filename bypasses the path-parameter guard, allowing authenticated attackers to write files anywhere on the host system, leading to Remote Code Execution (RCE). Version 1.9.0 contains an updated fix.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-73CWE-94CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-03-24)
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-03-19: 1Mentions · 2026-03-20: 2Mentions · 2026-03-24: 3PoC Mentioned / Linked · 2026-03-24: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-24: 203-1903-2003-24
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-191
Disclosure1
2026-03-202
Disclosure2
2026-03-243
Disclosure1General1Patch1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    Two critical flaws in Langflow (CVE-2026-33017 & CVE-2026-33309) allow unauthenticated remote code execution and arbitrary file writes. Secure servers now. #Langflow #CVE #CyberSecurity #InfoSec #AISecurity #RCE #Vulnerability #TechNews https://securityonline.info/critical-langflow-vulnerabilities-rce-file-write-cve-2026-33017/ https://t.co/4HpoRNDfgW

    Post summary

    The tweet announces two newly disclosed, critical flaws in Langflow that enable unauthenticated remote code execution and arbitrary file writes, but it does not provide PoC code, exploit tools, or patch information.

    02051340
    10.7K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33309 Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68478 (External Co… https://www.cve.org/CVERecord?id=CVE-2026-33309

    Post summary

    The snippet lists CVE‑2026‑33309 and notes a patch bypass for a different CVE but offers no technical or exploit details.

    00000137
    56.8K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33309: Langflow has an Arbitrary File W... Patch bypass via multipart filename sidesteps ValidatedFileName guard—defense-in-depth failure turns authenticated user... https://zerodaysignal.com/vulnerability/CVE-2026-33309 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-33309 in Langflow, highlighting an arbitrary file upload vulnerability that can bypass the ValidatedFileName guard via multipart filenames, with a link to further details.

    0000078
    164 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33309: CRITICAL] Langflow, a tool for AI-powered workflows, has a security flaw in versions 1.2.0 to 1.8.1 allowing Remote Code Execution. Update to version 1.9.0 for the fixed vulnerability.#cve,CVE-2026-33309,#cybersecurity https://cvefind.com/CVE-2026-33309

    Post summary

    A critical remote code execution flaw affects Langflow versions 1.2.0–1.8.1; users are urged to upgrade to 1.9.0 to remediate the issue.

    0000040
    606 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An arbitrary file write vulnerability (CVE-2026-33309) impacting `Langflow` via its v2 API may lead to RCE. Assess exposure and restrict v2 API access. #Langflow #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-33309-langflow-rce

    Post summary

    The post highlights an arbitrary file write flaw in Langflow’s v2 API that could enable remote code execution, recommending users restrict API access and directing them to a linked article for more details.

    0000040
    1 followersView on X
  • Vulert@vulert_official
    Disclosure

    🚨 Critical RCE Alert: CVE-2026-33309 in Langflow A serious arbitrary file write + Remote Code Execution (RCE) flaw in Langflow could let attackers compromise affected systems. 🔍 More details: https://vulert.com/vuln-db/CVE-2026-33309 #CyberSecurity #Langflow #CVE202633309 #OpenSourceSecurity https://t.co/Tw09MDAvOI

    Post summary

    Alert announces the CVE‑2026‑33309 RCE flaw in Langflow, noting its ability for arbitrary file writes and remote code execution.

    0000043
    123 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more