Web Hack List

Preliminary research

CVE-2026-33017: Unauthenticated RCE in Langflow through a surviving public execution path

AI-collected research leads through 2 October 2026, including bounded month-by-month reviews of selected social and community sources from March through September. Unranked, incomplete, not community-vetted, and subject to change.

Traces attacker-supplied public-flow JSON through Langflow's graph builder to unsandboxed Python exec during component instantiation. The analysis shows why an earlier fix left a sibling public execution endpoint exposed and demonstrates a single-request unauthenticated exploit path.

Record

Researcher
aviral srivastava
Published by
DEV Community
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of aviral srivastava, first published at the original source. Preserved copies are kept so the citation survives its host.