
Tech
CVE-2026–17633 - Authenticated RCE in Langflow OSS via /api/v1/custom_component
Summary
Field
Value
CVE ID
CVE-2026-17633
CVSS
8.5 (HIGH)
CWE
CWE-94 (Improper Control of Generation of Code)
Affected
Langflow OSS 1.0.0 – 1.10.3
Preconditions
Any authenticated user + LANGFLOW_ALLOW_CUSTOM_COMPONENTS=true
Vulnerable endpoint
POST /api/v1/custom_component
Langflow is an open-source low-code platform for building LLM applications and agent workflows visually. One of its features, Custom Components ,...
Read the full discussion on Dev.to
This article was aggregated from Dev.to. Click to join the conversation.
View on Dev.to