ID:12508 - Exploit for External Control of File Name or Path in Langflow - CVE-2026-33309

 
Main Vulnerability Database Exploits ID:12508 - Exploit for External Control of File Name or Path in Langflow - CVE-2026-33309

ID:12508 - Exploit for External Control of File Name or Path in Langflow - CVE-2026-33309

Published: March 19, 2026


Vulnerability identifier: #VU124127
Vulnerability risk: Medium
CVE-ID: CVE-2026-33309
CWE-ID: CWE-73
Exploitation vector: Remote access
Vulnerable software:
Langflow

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to write arbitrary files.

The vulnerability exists due to external control of file name or path within LocalStorageService. A remote user can write files anywhere on the host system and execute arbitrary code on the target system.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.