CVE-2026-33017

Langflow: Code Injection

As of , CVE-2026-33017 in Langflow is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 25 March 2026
US federal deadline
8 April 202614 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.25Higher than 97% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
Public exploit
1 Metasploit module and 1 Exploit-DB entry
Fix
Vendor advice: github.comLinks below, from CISA's entry.

What CISA says to do

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA's required action

What the flaw is

Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.

CISA's description

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.

The CVE record's description, from GitHub_M

CVE published
20 March 2026
Assigned by
GitHub_M
CVSS
9.3 Critical (CVSS 4.0, from the CNA)
CWE-94
Improper Control of Generation of Code ('Code Injection')
CWE-95
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
CWE-306
Missing Authentication for Critical Function
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.
  4. Exploit-DB published an exploit (EDB-ID 52627).

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

Langflow: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-0770Inclusion of Functionality from Untrusted Control SphereLangflow LangflowPatch nowForensic triage required by CISA; Metasploit module0.63
CVE-2026-55255Authorization Bypass Through User-Controlled KeyLangflow LangflowPatch nowForensic triage required by CISA0.01
CVE-2025-3248Missing AuthenticationLangflow LangflowPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2025-34291Origin Validation ErrorLangflow LangflowPatch this weekEPSS 0.930.93

Read further