CVE-2026-33873Disclosure(langflow / langflow)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assistant feature in Langflow executes LLM-generated Python code during its validation phase. Although this phase appears intended to validate generated component code, the implementation reaches dynamic execution sinks and instantiates the generated class server-side. In deployments where an attacker can access the Agentic Assistant feature and influence the model output, this can result in arbitrary server-side Python execution. Version 1.9.0 fixes the issue.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-27); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-27: 2Mentions · 2026-03-28: 1PoC Mentioned / Linked · 2026-03-27: 1Technical Details · 2026-03-27: 203-2703-28
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-272
Disclosure2
2026-03-281
General1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-33873 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assistant feature in Langflow executes LLM-generate… https://www.cve.org/CVERecord?id=CVE-2026-33873

    Post summary

    The entry notes CVE-2026-33873 relating to a pre‑1.9.0 feature in Langflow, but provides no concrete technical detail, evidence of exploitation, or mitigation guidance.

    10000115
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33873: Langflow has Authenticated Code ... LLM prompt injection meets server-side RCE - attackers can manipulate AI output to execute arbitrary Python during "val... https://zerodaysignal.com/vulnerability/CVE-2026-33873 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    Langflow’s CVE‑2026‑33873 allows authenticated users to inject prompts that trigger server‑side RCE, enabling arbitrary Python execution, with no active exploitation or patch reported so far.

    0000070
    194 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An authenticated code execution vulnerability in `Langflow` (CVE-2026-33873) may allow arbitrary code execution via Agentic Assistant Validation. Organizations should review access controls and monitor for updates. #AppSec #CodeExecution #Langflow https://www.pulsepatch.io/posts/cve-2026-33873-langflow-authenticated-code-execution

    Post summary

    The post announces an authenticated code‑execution vulnerability in Langflow, urging organizations to review controls and watch for vendor updates.

    0000035
    6 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more