Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') The advisory has been revoked - it doesn't affect any version of package langflow  (opens in a new tab)


Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
2.96% (86th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-LANGFLOW-15762990
  • published24 Mar 2026
  • disclosed24 Mar 2026
  • credithuseyingulsin

Introduced: 24 Mar 2026

CVE-2026-33475  (opens in a new tab)
CWE-74  (opens in a new tab)

Amendment

This was deemed not a vulnerability.

Overview

langflow is an A Python package with a built-in web application

Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via unsanitized interpolation of GitHub context variables in run steps within workflow files. An attacker can execute arbitrary shell commands and exfiltrate CI secrets by submitting a pull request or branch with a crafted name or title.