Junglewise Threat Intelligence

CVE-2026-33497: Langflow path traversal in profile picture endpoint

CVE-2026-33497 · Severity: high · CVSS 4 · Published 2026-03-20

Technologies: Langflow-Ai Langflow, langflow (PyPI). Vendors: Langflow, PyPI.

Executive brief

Langflow, a framework for building multi-agent AI applications, contains a security flaw in how it handles profile picture requests. An unauthenticated attacker can use this flaw to read sensitive files from the server's filesystem, including the application's secret keys. Access to these keys could allow an attacker to bypass authentication entirely and take control of any user account, including administrators.

Technical details

A path traversal vulnerability exists in the `download_profile_picture` function within `src/backend/base/langflow/api/v1/files.py`. The application fails to sanitize the `folder_name` and `file_name` path parameters before concatenating them to a base directory path. An unauthenticated attacker can use `../` sequences to escape the intended directory and read arbitrary files, such as the `secret_key` file used for JWT signing. This exfiltration enables the forgery of administrative tokens. The issue is fixed in version 1.7.1 by implementing typed path validation and strict path containment checks using `Path.is_relative_to()`.

Affected products

  • langflow-ai langflow < 1.7.1

Timeline

  • 2026-03-20: disclosed
  • 2026-03-20: advisory
  • 2026-03-20: patched: Fixed in version 1.7.1

References

Related threats