CVE-2026-33497 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_profile_picture function of the /profile_…
High CVSS: 8.7

CVE-2026-33497

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_profile_picture function of the /profile_pictures/{folder_name}/{file_name} endpoint, the folder_name and file_name parameters are not strictly filtered, which allows the secret_key to be read across directories. Version 1.7.1 contains a patch.
Vendor
Langflow
Product
Langflow
CWE
CWE-22
Yayın Tarihi
2026-03-24 14:16:30
Güncelleme
2026-03-24 19:20:25
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar