Code injection in Langflow - CVE-2026-33017
Published: March 27, 2026 / Updated: April 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation at the "/api/v1/build_public_tmp/{flow_id}/flow" endpoint. A remote attacker can send a specially crafted HTTP POST request to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
How to mitigate CVE-2026-33017
Links to Public Exploits and PoC-codes
- Exploit #12603 - PoC-CVE-2026-33017 (Proof-of-concept exploit for CVE-2026-33017 (Langflow <= 1.8.1).) (April 17, 2026)
- Exploit #12575 - CVE-2026-33017-Langflow-PoC (Proof-of-concept exploit for CVE-2026-33017 (Langflow <= 1.8.1).) (April 10, 2026)
- Exploit #12573 - CVE-2026-33017-Exploit (CVE-2026-33017 | Langflow Unauthenticated RCE (CVSS 9.8) | Blind exec, OOB exfil (GET/POST), reverse shell, auto-promote, bulk scanner) (April 10, 2026)
- Exploit #12538 - langflow-CVE-2026-33017-poc (A proof-of-concept exploiting an unauthenticated remote code execution in Langflow <= 1.8.1 via Public Flow Build Endpoint) (April 1, 2026)
- Exploit #12537 - Sovereign-Echo-33017 (Resonant RCE for CVE-2026-33017 via CTT Phase-Lock. Exploits Langflow build_public_tmp flow_id endpoint. Bypasses auth using 34th-layer negative refraction to inject Python exec() payloads. Calibrated for 16.6fs jitter resonance and (April 1, 2026)