Detects Langflow instances prior to 1.9.0 where the build_public_tmp endpoint accepts attacker-controlled flow definitions containing arbitrary Python code. The code is passed to exec() without sandboxing, enabling unauthenticated remote code execution. Actively exploited within 20 hours of disclosure.
Is your app exploitable through CVE-2026-33017?
Scan your domain free