CVE-2026-33497 Scanner
CVE-2026-33497 Scanner - Path Traversal vulnerability in Langflow
Used 2.6k times · 5.9k assets checked · url
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_profile_picture function of the /profile_pictures/{folder_name}/{file_name} endpoint, the folder_name and file_name parameters are not strictly filtered, which allows the secret_key to be read across directories. Version 1.7.1 contains a patch.
CVE-2026-33497 Scanner - Path Traversal vulnerability in Langflow
Used 2.6k times · 5.9k assets checked · url
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →