CVE-2026-33309 | langflow-ai langflow up to 1.8.1 Incomplete Fix CVE-2025-68478 /api/v2/files/ path traversal
A vulnerability identified as critical has been detected in langflow-ai langflow up to 1.8.1. Affected is an unknown function of the file /api/v2/files/ of the component Incomplete Fix CVE-2025-68478. Performing a manipulation results in path traversal.
This vulnerability is known as CVE-2026-33309. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.