Langflow versions prior to 1.9.0 are vulnerable to unauthenticated remote code execution (RCE) via the build_public_tmp endpoint. Attackers can submit a manipulated flow JSON containing Python code that is executed during the build process without proper sandboxing.
id: CVE-2026-33017
info:
name: Langflow < 1.9.0 - Remote Code Execution
author: himind
severi
...