CVE-2026-33017

critical KEV
Published 2026-03-20 · Modified 2026-03-25
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
10.0

Description

Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.

CISA KEV

Vendor
Langflow
Product
Langflow
Due date
2026-04-08

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx ; https://nvd.nist.gov/vuln/detail/CVE-2026-33017

vendor Authored 2026-05-27

Vendor advisory: 134c704f-9b21-4f2e-91b3-4a467353bcc0 — https://github.com/langflow-ai/langflow/releases/tag/1.8.2

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/langflow-ai/langflow/commit/73b6612e3ef25fdae0a752d75b0fabd47328d4f0

Exploits

Package impact

EcosystemPackageVulnerableFixed
python PyPIlangflow<=1.8.2

Application impact

VendorProductVersionsFixed
langflowlangflow{"endExcluding":"1.8.2"}1.8.2

References

CWEs

CWE-94 CWE-95 CWE-306

Verify integrity in audit chain (admin only). AS-IS.