Vulnerability  ·  2026-10-07

Langflow MCP stdio transport RCE cluster — arbitrary OS command execution on the server (unauthenticated under default AUTO_LOGIN)

VulnerabilityHigh impactGlobalCVE-2026-105697
Langflow's MCP 'Stdio' transport executed whatever command/args a user placed in an MCP server configuration, wrapped in `bash -c exec …` with no allowlist or sandboxing; the command runs as the Langflow process user the moment the server list is fetched or a flow uses the MCP tools component. With the default LANGFLOW_AUTO_LOGIN=true an exposed instance hands out a token without any credentials, so CVE-2026-105697 is effectively unauthenticated. A related authenticated pre-1.9.0 variant (CVE-2026-105740) also allowed arbitrary environment-variable injection (LD_PRELOAD/PATH). The broader Oct 5 disclosure batch also covered an X-Forwarded-For: 127.0.0.1 spoof that bypasses the local-only MCP install restriction (105741), cross-tenant MCP resource reads (105699) and flow build/vertex ownership gaps (105698).
Langflow is one of the most widely deployed open-source agent/workflow builders (used to wire MCP tool surfaces into LLM apps). Any user — or anyone reaching an instance with the default auto-login — can execute arbitrary commands on the serving host, steal secrets and model/provider credentials, and pivot into the surrounding environment via the agent-build surface itself.
Add an MCP server in Settings → MCP Servers (POST/PATCH /api/v2/mcp/servers/{server_name}) or build a flow using the MCP Tools component, setting the command field to an arbitrary OS command; fetched tool lists/flow runs on the Langflow host as the process user (or use build vertices).
Langflow / langflow-base / lfx < 1.10.3 (CVE-2026-105697); < 1.9.0 (CVE-2026-105740); also CVE-2026-105741 IP-spoofing bypass < 1.10.3, CVE-2026-105699 MCP resource cross-tenant read 1.6.8–1.9.1, CVE-2026-105698 build-vertices flow ownership 1.0.0–1.10.1
Upgrade to Langflow 1.10.3 / langflow-base 0.10.3 / lfx 1.10.3 (105697,105741), 1.9.0 (105740), 1.9.1 (105699), 1.10.1 (105698). Disable AUTO_LOGIN on exposed instances; restrict who can create MCP server configs.
NVD CVE-2026-105697Langflow advisory GHSA-w794-rj3p-xv45NVD CVE-2026-105740ThreatFrontier Langflow MCP Stdio RCE analysis
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →