Arbitrary File Write Vulnerability in Langflow Software by Langflow AI
CVE-2026-33309
10CRITICAL
What is CVE-2026-33309?
Langflow, a tool designed for building AI-powered agents, has a significant security vulnerability affecting versions 1.2.0 through 1.8.1. This flaw arises from a bypass of a previous patch, exposing the application's core architecture. The absence of adequate boundary checks in the LocalStorageService permits malicious actors to exploit the POST /api/v2/files/ endpoint. By manipulating multipart upload file names, authenticated attackers can overwrite files on the host system, resulting in potential Remote Code Execution. It is essential for users of Langflow to upgrade to version 1.9.0, which includes a remedy for this issue.
Affected Version(s)
langflow >= 1.2.0, < 1.9.0
