CVE-2026-33017 (CVSS 9.3): unauthenticated RCE in Langflow <1.9.0 via POST /api/v1/build_public_tmp/{flow_id}/flow. Optional data parameter substitutes attacker-controlled flow definitions passed to unsandboxed exec().
Sysdig TRT documented exploitation within ~20 hours of advisory. Attackers steal cloud API keys and database credentials from exposed instances.
Distinct from CVE-2025-3248 (authenticated /validate/code). Fix: upgrade to 1.9.0+ or block build_public_tmp at WAF/perimeter. Langflow has 145K+ GitHub stars. Not yet in CISA KEV catalog despite active exploitation.