Main
Vulnerability Database
Exploits
ID:12508 - Exploit for External Control of File Name or Path in Langflow - CVE-2026-33309
ID:12508 - Exploit for External Control of File Name or Path in Langflow - CVE-2026-33309
Published: March 19, 2026
Vulnerability identifier: #VU124127
Vulnerability risk: Medium
CVE-ID: CVE-2026-33309
CWE-ID: CWE-73
Exploitation vector: Remote access
Vulnerable software:
Langflow
Langflow
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to write arbitrary files.
The vulnerability exists due to external control of file name or path within LocalStorageService. A remote user can write files anywhere on the host system and execute arbitrary code on the target system.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.