CVE-2026-33017
CRITICAL(9.8)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 9.8 — Kritisch
- EPSS 96% — sehr wahrscheinlich ausgenutzt
- Im CISA KEV-Katalog (aktiv ausgenutzt)
Erwähnungen (letzte 60 Tage)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
96.2%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
SecBoard-Einordnung
CVE-2026-33017 betrifft Langflow, ein Tool zum Erstellen und Bereitstellen von KI-Agenten und Workflows. Die Schwachstelle ermöglicht unauthentifizierte Remote Code Execution (RCE) über den POST /api/v1/build_public_tmp/{flow_id}/flow-Endpunkt. Angreifer können bösartigen Python-Code in den Node-Definitionen über den 'data'-Parameter einschleusen, der dann ohne Sandboxing ausgeführt wird.
Diese Schwachstelle ist mit einem CVSS-Score von 9.8 (CRITICAL) und einer EPSS-Wahrscheinlichkeit von 96% als extrem kritisch einzustufen. Sie wird aktiv ausgenutzt und ist im CISA Known Exploited Vulnerabilities (KEV) Katalog gelistet, was eine sofortige Handlungsnotwendigkeit unterstreicht.
Security-Teams sollten umgehend alle Langflow-Instanzen auf Version 1.9.0 oder höher aktualisieren, um diese kritische RCE-Schwachstelle zu beheben. Eine schnelle Priorisierung und Implementierung des Patches ist aufgrund der aktiven Ausnutzung und des hohen Risikoprofils unerlässlich.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.
GitHub Advisories
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
In diesen Analysen erwähnt
Referenzen
- https://github.com/advisories/GHSA-rvqx-wpfh-mfx7
- https://github.com/langflow-ai/langflow/commit/73b6612e3ef25fdae0a752d75b0fabd47...
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx
- https://github.com/langflow-ai/langflow/releases/tag/1.8.2
- https://medium.com/@aviral23/cve-2026-33017-how-i-found-an-unauthenticated-rce-i...
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-...
- https://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai...