# CVE-2026-33497: Langflow - Path Traversal

> Live exploitation tracking for CVE-2026-33497 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-33497

## Key facts

- **Exploitation phase:** Background Noise. Continuous low-level scanning or exploitation attempts are observed, mostly opportunistic and automated.
- **CVSS score:** 8.7
- **Public exploit available:** Yes
- **Affected products:** Langflow
- **Weaknesses:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
- **Tags:** ai_mcp, python, web_application

## Description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_profile_picture function of the /profile_pictures/{folder_name}/{file_name} endpoint, the folder_name and file_name parameters are not strictly filtered, which allows the secret_key to be read across directories. Version 1.7.1 contains a patch.

## CrowdSec analysis

[CVE-2026-33497](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-33497) is a high-severity path traversal vulnerability in langflow versions before 1.7.1. Insufficient filtering of the `folder_name` and `file_name` parameters in the profile picture download endpoint allows unauthenticated remote attackers to access files across directories, including the application’s secret key, potentially enabling further compromise.

CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.

CrowdSec network data shows that most actors exploiting CVE-2026-33497 rely on broad, untargeted scans with minimal filtering. The activity is largely automated and opportunistic in nature.
Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2026-33497. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.

Attackers target the `/api/v1/files/profile_pictures/` endpoint with `../` path traversal sequences to access sensitive files such as `secret_key` outside the intended directory. Successful exploitation may return the file with an HTTP 200 response and an `application/octet-stream` content type.

## Timeline

- 2026-03-24: CVE Published. CVE-2026-33497 is published to NVD.
- 2026-08-03: Rule Released. CrowdSec releases a rule to detect CVE-2026-33497 exploitation attempts against the CrowdSec Network.
- 2026-08-19: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-33497 for the first time.

## References

- https://github.com/langflow-ai/langflow/security/advisories/GHSA-ph9w-r52h-28p7
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-33497.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-33497) follows observed exploitation activity for CVE-2026-33497. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
