¡¾Îó²îͨ¸æ¡¿Langflow δÊÚȨԶ³Ì´úÂëÖ´ÐÐÎó²î(CVE-2026-33017)

Ðû²¼Ê±¼ä 2026-03-23

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Langflow δÊÚȨԶ³Ì´úÂëÖ´ÐÐÎó²î

CVE   ID

CVE-2026-33017

Îó²îÀàÐÍ

RCE

·¢Ã÷ʱ¼ä

2026-3-23

Îó²îÆÀ·Ö

9.3

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


LangflowÊÇÒ»¿î»ùÓÚLangChainµÄ¿ªÔ´µÍ´úÂëAIÓ¦ÓñàÅÅÆ½Ì¨£¬£¬£¬£¬£¬£¬£¬Ö§³Öͨ¹ý¿ÉÊÓ»¯·½·¨¹¹½¨LLMÊÂÇéÁ÷£¨flows£©£¬£¬£¬£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚ¶Ô»°ÏµÍ³¡¢Êý¾Ý´¦Öóͷ£¼°×Ô¶¯»¯Ê¹Ãü³¡¾°¡£¡£¡£¡£¡£¡£¡£Æä½¹µã¹¦Ð§°üÀ¨½ÚµãʽÁ÷³ÌÉè¼Æ¡¢×é¼þÀ©Õ¹¡¢Ä£×Ó¼¯³É¼°APIЧÀÍÐû²¼£¬£¬£¬£¬£¬£¬£¬ÊÊÓÃÓÚAIÓ¦Óÿª·¢Óë¿ìËÙÔ­Ð͹¹½¨¡£¡£¡£¡£¡£¡£¡£


2026Äê3ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½Langflow δÊÚȨԶ³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îλÓÚ/api/v1/build_public_tmp/{flow_id}/flow½Ó¿Ú£¬£¬£¬£¬£¬£¬£¬ÓÉÓڸýӿÚδ¾ÙÐÐÉí·ÝÈÏÖ¤ÇÒÔÊÐí¹¥»÷Õßͨ¹ýdata²ÎÊýÌá½»¿É¿ØflowÊý¾Ý£¬£¬£¬£¬£¬£¬£¬µ¼Ö¶ñÒâPython´úÂë±»Ö±½Ó´«Èëexec()Ö´ÐÐÇÒȱ·¦ÈκÎɳÏä¸ôÀë¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß½öÐè»ñÈ¡public flowµÄUUID²¢½á¹¹¶ñÒâÇëÇ󣬣¬£¬£¬£¬£¬£¬¼´¿ÉÔÚЧÀÍÆ÷¶ËÖ´ÐÐí§ÒâϵͳÏÂÁ£¬£¬£¬£¬£¬£¬»ñȡЧÀÍÆ÷ȨÏÞ¡¢¶ÁÈ¡»ò¸Ä¶¯Ãô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢½øÒ»²½ºáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°Ïì¹æÄ£¹ã£¬£¬£¬£¬£¬£¬£¬Î£º¦¼«¸ß£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢ÓªÒµÏµÍ³Ê§ÏÝ£¬£¬£¬£¬£¬£¬£¬ÉõÖÁÎ¥·´Êý¾ÝÇå¾²ÓëÒþ˽ºÏ¹æÒªÇ󣬣¬£¬£¬£¬£¬£¬¶ÔÆóÒµºÍÓû§Ôì³ÉÑÏÖØÇå¾²Íþв¡£¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Langflow <= 1.8.1


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£
Langflow >= 1.9.0


ÏÂÔØÁ´½Ó£ºhttps://github.com/langflow-ai/langflow/releases/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx/
https://nvd.nist.gov/vuln/detail/CVE-2026-33017