EXECUTIVE SUMMARY:
Two vulnerabilities were observed in the popular open-source AI workflow platform Langflow. The first is a high severity path traversal flaw that allowed attackers to read sensitive secret key files and forge JWT authentication tokens due to insufficient filtering of file path parameters. The second is a critical unauthenticated remote code execution (RCE) vulnerability in a public API endpoint that accepts attacker-controlled flow data and executes it using Python exec() with no sandboxing, enabling attackers to run arbitrary code and extract credentials and was actively exploited in the wild of disclosure.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Two vulnerabilities were observed in the popular open-source AI workflow platform Langflow. The first is a high severity path traversal flaw that allowed attackers to read sensitive secret key files and forge JWT authentication tokens due to insufficient filtering of file path parameters. The second is a critical unauthenticated remote code execution (RCE) vulnerability in a public API endpoint that accepts attacker-controlled flow data and executes it using Python exec() with no sandboxing, enabling attackers to run arbitrary code and extract credentials and was actively exploited in the wild of disclosure.[emaillocker id="1283"]
RECOMMENDATION:
We strongly recommend you update Langflow to below version:
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2026/03/critical-langflow-flaw-cve-2026-33017.html
[/emaillocker]