FixVibe

critical

Unauthenticated RCE in Langflow via Public Flow Build Endpoint (CVE-2026-33017)

Langflow 1.8.2 and earlier are associated with CVE-2026-33017 / GHSA-vwmf-pq79-vjvx. FixVibe verified active scans flag Langflow deployments that publicly report an affected version and guide teams to upgrade to 1.9.0 or newer.

CVE-2026-33017GHSA-vwmf-pq79-vjvxCWE-94CWE-95CWE-306

Impact

Langflow 1.8.2 and earlier are associated with unauthenticated remote code execution risk in the public flow-build behavior described by CVE-2026-33017 / GHSA-vwmf-pq79-vjvx [S2]. A publicly reachable affected Langflow instance can put application data, integrations, stored secrets, and the host environment at risk.

Root Cause

The advisory describes affected Langflow releases accepting untrusted public flow-build input and processing it in a way that can cross into Python code execution [S2]. The fixed release line closes that unauthenticated exposure and should be treated as the primary remediation [S2].

Remediation

Upgrade Langflow to 1.9.0 or newer and redeploy or restart the runtime that actually serves traffic [S2]. Until the fixed runtime is live, require authentication or trusted-network access for the Langflow UI and API, and block unauthenticated public flow-build access at the edge where feasible. If the instance was internet-reachable while running an affected version, review flows, access logs, and stored secrets before closing the incident.

Covered by FixVibe

FixVibe's verified active scans flag Langflow deployments on your domain that publicly report an affected release, so you can upgrade to 1.9.0 or newer.