Skip to content

Known CVE

Langflow < 1.7.0 - Path Traversal

Langflow < 1.7.1 contains a path traversal caused by insufficient filtering of folder_name and file_name parameters in download_profile_picture endpoint, letting attackers read secret_key across directories, exploit requires crafted request.

CVE-2026-33497

High2026CVSS 7.5CWE-22

cve2026 · langflow · traversal · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website