Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the downloadprofilepicture function of the /profilepictures/{foldername}/{filename} endpoint, the foldername and filename parameters are not strictly filtered, which allows the secretkey to be read across directories. Version 1.7.1 contains a patch.