References https://github.com/langflow-ai/langflow/security/advisories/GHSA-ph9w-r52h-28p7 https://nvd.nist.gov/vuln/detail/CVE-2026-33497 https://advisories.gitlab.com/pypi/langflow/CVE-2026-33497/ https://codepathfinder.dev/blog/langflow-knowledge-bases-path-traversal-variant-analysis https://db.gcve.eu/vuln/CVE-2026-33497 https://www.codeant.ai/vulnerability-database/cve-2026-33497 https://github.com/advisories/GHSA-ph9w-r52h-28p7
Related VulnerabilitiesPoClangflow-api-exposure: Langflow - Unauthenticated API ExposurePoCCVE-2026-0768: Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_codeLangflow /api/v1/custom_component 代码执行漏洞(CVE-2024-37014)PoCCVE-2024-37014: Langflow <= 1.0.12 - Remote Code ExecutionIBM Langflow OSS 远程代码执行漏洞(CVE-2026-9198)PoCCVE-2026-55450: Langflow < 1.9.1 - Unauthenticated File UploadPoCCVE-2026-33497: Langflow < 1.7.0 - Path TraversalPoCCVE-2026-9198: IBM Langflow - Remote Code ExecutionLangflow build_public_tmp 代码执行漏洞(CVE-2026-33017)PoCCVE-2026-5027: Langflow <= 1.8.4 - Path Traversal to RCE via File UploadLangflow /api/v2/files 文件上传漏洞(CVE-2026-5027)Langflow /api/v1/validate/code 代码执行漏洞(CVE-2026-0770)PoCCVE-2026-33017: Langflow < 1.9.0 - Remote Code Execution