Gray Hats@the_yellow_fallDisclosure
The tweet announces two newly disclosed, critical flaws in Langflow that enable unauthenticated remote code execution and arbitrary file writes, but it does not provide PoC code, exploit tools, or patch information.
CVE@CVEnewGeneral
The snippet lists CVE‑2026‑33309 and notes a patch bypass for a different CVE but offers no technical or exploit details.
0day Signal@0dayPublishingDisclosure
The tweet announces CVE-2026-33309 in Langflow, highlighting an arbitrary file upload vulnerability that can bypass the ValidatedFileName guard via multipart filenames, with a link to further details.
CVEFind.com@CveFindComPatch
A critical remote code execution flaw affects Langflow versions 1.2.0–1.8.1; users are urged to upgrade to 1.9.0 to remediate the issue.
PulsePatch.io@pulsepatchioDisclosure
The post highlights an arbitrary file write flaw in Langflow’s v2 API that could enable remote code execution, recommending users restrict API access and directing them to a linked article for more details.
Vulert@vulert_officialDisclosure
Alert announces the CVE‑2026‑33309 RCE flaw in Langflow, noting its ability for arbitrary file writes and remote code execution.