CrowdSecLive Exploit Tracker
Background NoiseCVE-2026-33497Public Exploit

Langflow - Path Traversal (CVE-2026-33497)

PublishedMar 24, 2026
First SeenAug 19, 2026
Last Seen
Reported
CVSS8.7
ai_mcppythonweb_application

Description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_profile_picture function of the /profile_pictures/{folder_name}/{file_name} endpoint, the folder_name and file_name parameters are not strictly filtered, which allows the secret_key to be read across directories. Version 1.7.1 contains a patch.

psychologyCrowdSec Analysis

CVE-2026-33497 is a high-severity path traversal vulnerability in langflow versions before 1.7.1. Insufficient filtering of the folder_name and file_name parameters in the profile picture download endpoint allows unauthenticated remote attackers to access files across directories, including the application’s secret key, potentially enabling further compromise.

CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.

CrowdSec network data shows that most actors exploiting CVE-2026-33497 rely on broad, untargeted scans with minimal filtering. The activity is largely automated and opportunistic in nature. Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2026-33497. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.

Attackers target the /api/v1/files/profile_pictures/ endpoint with ../ path traversal sequences to access sensitive files such as secret_key outside the intended directory. Successful exploitation may return the file with an HTTP 200 response and an application/octet-stream content type.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-03-24
Rule Released2026-08-03
CrowdSec First Seen2026-08-19

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.