Directory Traversal Vulnerability in Langflow by Langflow AI
CVE-2026-33497
8.7HIGH
What is CVE-2026-33497?
Langflow, a platform for building AI-powered agents and workflows, has a vulnerability related to insufficient parameter filtering in its download_profile_picture function. This issue allows attackers to exploit the /profile_pictures/{folder_name}/{file_name} endpoint, potentially leading to unauthorized access to the secret_key across directories. Version 1.7.1 of Langflow addresses this issue with a security patch, reinforcing protection against such exploitation.
Affected Version(s)
langflow < 1.7.1
