Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g2j9-7rj2-gm6c | Langflow has an Arbitrary File Write (RCE) via v2 API |
Tue, 24 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langflow
Langflow langflow |
|
| CPEs | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Langflow
Langflow langflow |
Tue, 24 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Mar 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68478 (External Control of File Name), leading to the root architectural issue within `LocalStorageService` remaining unresolved. Because the underlying storage layer lacks boundary containment checks, the system relies entirely on the HTTP-layer `ValidatedFileName` dependency. This defense-in-depth failure leaves the `POST /api/v2/files/` endpoint vulnerable to Arbitrary File Write. The multipart upload filename bypasses the path-parameter guard, allowing authenticated attackers to write files anywhere on the host system, leading to Remote Code Execution (RCE). Version 1.9.0 contains an updated fix. | |
| Title | Langflow has an Arbitrary File Write (RCE) via v2 API | |
| Weaknesses | CWE-22 CWE-284 CWE-73 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-25T03:55:47.098Z
Reserved: 2026-03-18T21:23:36.675Z
Link: CVE-2026-33309
Updated: 2026-03-24T17:47:08.500Z
Status : Analyzed
Published: 2026-03-24T13:16:02.983
Modified: 2026-03-24T19:17:15.510
Link: CVE-2026-33309
No data.
OpenCVE Enrichment
Updated: 2026-03-25T20:50:19Z
Github GHSA