Arbitrary File Write Vulnerability in Langflow Software by Langflow AI
CVE-2026-33309

10CRITICAL

Key Information:

Status
Vendor
CVE Published:
24 March 2026

What is CVE-2026-33309?

Langflow, a tool designed for building AI-powered agents, has a significant security vulnerability affecting versions 1.2.0 through 1.8.1. This flaw arises from a bypass of a previous patch, exposing the application's core architecture. The absence of adequate boundary checks in the LocalStorageService permits malicious actors to exploit the POST /api/v2/files/ endpoint. By manipulating multipart upload file names, authenticated attackers can overwrite files on the host system, resulting in potential Remote Code Execution. It is essential for users of Langflow to upgrade to version 1.9.0, which includes a remedy for this issue.

Affected Version(s)

langflow >= 1.2.0, < 1.9.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.