CVE-2026-33484 | langflow-ai langflow up to 1.8.x Image /api/v1/files/images/ flow_id access control
A vulnerability labeled as critical has been found in langflow-ai langflow up to 1.8.x. This impacts an unknown function of the file /api/v1/files/images/ of the component Image Handler. Executing a manipulation of the argument flow_id can lead to improper access controls.
This vulnerability appears as CVE-2026-33484. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.