Arbitrary File Write Vulnerability in Langflow Software by Langflow AI
CVE-2026-33309
What is CVE-2026-33309?
Langflow, a tool designed for building AI-powered agents, has a significant security vulnerability affecting versions 1.2.0 through 1.8.1. This flaw arises from a bypass of a previous patch, exposing the application's core architecture. The absence of adequate boundary checks in the LocalStorageService permits malicious actors to exploit the POST /api/v2/files/ endpoint. By manipulating multipart upload file names, authenticated attackers can overwrite files on the host system, resulting in potential Remote Code Execution. It is essential for users of Langflow to upgrade to version 1.9.0, which includes a remedy for this issue.
Affected Version(s)
langflow >= 1.2.0, < 1.9.0
References
EPSS Score
12% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
