CVE-2026-33497 | langflow-ai langflow up to 1.7.0 Parameter /profile_pictures/ download_profile_picture file_name path traversal
A vulnerability marked as critical has been reported in langflow-ai langflow up to 1.7.0. Affected is the function download_profile_picture of the file /profile_pictures/ of the component Parameter Handler. The manipulation of the argument file_name leads to path traversal.
This vulnerability is traded as CVE-2026-33497. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.