high Langflow · AI Security

Langflow MCP Stdio Flaws Give Any Logged-In User a Shell: CVE-2026-105697 and CVE-2026-105740

CVSS 9.9 rating for Langflow MCP stdio command-injection flaws, fixed in 1.10.3; no exploitation reported, not in CISA KEV.
AK

Threat intelligence editor · Published Oct 5, 2026, 9:42 PM EDT

Two CVSS 9.9 command-injection flaws in Langflow's MCP stdio transport let a low-privileged user run host commands. Fixed in 1.10.3; no exploitation reported.

Two critical command-injection flaws in Langflow's MCP stdio transport let a low-privileged user run operating-system commands on the server. GitHub scored both CVSS 3.1 9.9 (AV:N/AC:L/PR:L/UI:N/S:C). NVD published both records on 5 October 2026 and has not scored them. We found no report of exploitation, and neither CVE is in CISA's Known Exploited Vulnerabilities (KEV) catalog.

The fix is Langflow 1.10.3 or later. The latest release we checked is 1.12.4, published 29 September 2026.

Who is affected

CVE-2026-105697 (GHSA-w794-rj3p-xv45) covers langflow from 1.1.2 up to but excluding 1.10.3, langflow-base from 0.1.2 up to 0.10.3, and lfx before 1.10.3. CVE-2026-105740 (GHSA-7w94-79vh-5mr2) is the earlier report. NVD lists it as affecting versions before 1.9.0, while the GitHub advisory names only 1.8.3 as the vulnerable version. Treat everything before 1.9.0 as exposed.

The advisory also says the reporter "found several internet-facing Langflow servers that were vulnerable". That means exposed and vulnerable, not exploited.

The advisory's exposure statement matters most. With the default LANGFLOW_AUTO_LOGIN=true, GET /api/v1/auto_login hands out a token without credentials. An exposed instance on default settings is therefore reachable without an account. Langflow documents AUTO_LOGIN as a development-only setting. With it disabled, any authenticated non-admin user can exploit the flaw.

What the bug is

Langflow lets users register MCP servers that run as local processes (the stdio transport; see our zero-trust MCP analysis for the wider protocol risks). In affected versions the command and args a user supplied were joined into a string and run as bash -c "exec {command} ...", with no allowlist. The advisory shows the code path in MCPStdioClient._connect_to_server. The command runs as the Langflow process user as soon as Langflow tries to connect: when it lists servers, loads tools or runs a flow. That happens even when the UI then reports that the server failed to start.

Entry points named in the advisories are the "Add MCP Server" settings page, POST and PATCH /api/v2/mcp/servers/{server_name}, and any flow built with the MCP Tools component. The 105740 advisory adds that a GET /api/v2/mcp/servers?action_count=true request, which the UI makes when the MCP settings page is opened, triggers the stored command. It also notes that the env field accepts arbitrary variables such as LD_PRELOAD and PATH. Both records are classed CWE-78 (OS command injection).

Attack path: a low-privileged user adds an MCP server, the command runs through bash -c exec with no allowlist, and a host command runs as the Langflow user.

How the flaw works. No exploitation reported.

Why 1.9.0 was not enough

The fix landed in two steps, per the GitHub advisory:

  • 1.9.0 (PR #12290) added a command allowlist plus argument and environment validation to the REST model MCPServerConfig. That blocks the "Add MCP Server" route. The advisory's fix section allows node, python, python3, npx, uvx and docker, and cmd, sh or bash only to wrap one of those. It adds shell-metacharacter checks and an environment blocklist covering LD_PRELOAD, NODE_OPTIONS, PYTHONPATH and BASH_ENV.
  • 1.10.3 (PR #14036, merged 14 July, released 23 July) applies one shared policy at the API, at flow execution and immediately before the process is spawned. It also removes the bash -c wrapper, so the process is started directly with no shell. The PR additionally rejects Docker host mounts and namespace options, blocks package-source and package-manager environment overrides, and checks shell-wrapper payloads recursively.

Between 1.9.0 and 1.10.2 the execution path still had no validation and still used the shell. According to the advisory, an MCP Tools value embedded in a flow, or passed as a tweak, could still run arbitrary commands. So 1.9.0 closes CVE-2026-105740 but not CVE-2026-105697.

Timeline: Langflow 1.9.0 Apr 14 fixed the REST path, 1.10.3 Jul 23 finished the fix 100 days later; advisory Sep 28; NVD Oct 5.

The two-step fix timeline.

How this compares with earlier Langflow flaws

Neither flaw has been reported as exploited, which separates them from several Langflow bugs that attackers have used. CISA's KEV catalog lists CVE-2026-33017, added 25 March 2026: an unauthenticated endpoint that built public flows from attacker-supplied code, which Langflow then ran with exec(). KEV also lists CVE-2025-3248, CVE-2025-34291, CVE-2026-55255, CVE-2026-0770 and CVE-2026-9198. Our earlier coverage of CVE-2026-33017 has the detail.

The new flaws differ in one respect: they need a session, not an open endpoint. That is a smaller barrier than it sounds, because the default auto-login setting removes it on exposed instances. CVE-2026-5027, a path-traversal file write that Google's threat intelligence group reported as exploited (our summary), is not in KEV, so KEV absence does not prove safety. The advisories also include a proof of concept, which shortens the time to a working attack.

What defenders should do

  1. Upgrade to langflow 1.10.3, langflow-base 0.10.3 and lfx 1.10.3 or later, ideally the current release (1.12.4 for all three). Versions between 1.9.0 and 1.10.2 remain vulnerable to CVE-2026-105697.
  2. Harden after patching. The advisory warns that the 1.10.3 allowlist still lets npx and uvx run any package by default. For multi-tenant deployments it recommends setting LANGFLOW_MCP_SERVER_ALLOWED_PACKAGES, LANGFLOW_MCP_SERVER_INTERPRETER_HARDENING=true and LANGFLOW_MCP_SERVER_DOCKER_HARDENING=true. On 1.11.1 and later, LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false, LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY=true or LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS=true also limits MCP stdio servers to superusers. Version 1.11.0 adds stricter modes.
  3. Turn off LANGFLOW_AUTO_LOGIN and keep Langflow off the public internet, behind SSO or a VPN.
  4. Limit who can create MCP servers and build flows. Anyone who can do either can run commands as the Langflow user on unpatched versions.
  5. Check for abuse on unpatched hosts. Review the MCP server settings, not just flows: configs are stored in project settings and are not visible during normal flow review, and a stored command re-runs every time the server list is loaded, including when other users or admins open the MCP settings page. Look for unfamiliar commands, env entries such as LD_PRELOAD, and child processes of the Langflow service. If you find any, rotate the model-provider keys and secrets the host holds. This is our inference from the access the flaw gives, not a finding in the advisories.

Open questions

NVD has not scored either record, and the 105740 version range differs between NVD and GitHub. We found no vendor or third-party report of exploitation as of 6 October 2026.

Sources

Keep reading

All latest →
  1. elevatedAI SecurityMCP Fetch Server SSRF (CVE-2026-104120) Has a Public Exploit and No Fix6 min
  2. elevatedAI Securityn8n Queue Mode: Redis Write Access Can Install Any npm Package on Every Instance (CVE-2026-103251)5 min
  3. elevatedAI SecurityLangGraph SDK Auth Bug: `actions=` Ignored on `@auth.on` Handlers (CVE-2026-104873)6 min
  4. highAI SecurityVibe-Trading AI Agent Flaws Chain an Open API to Root Code Execution8 min
  5. highAI SecurityGoogle GTIG Counts 141 Exploited Flaws in 8 Months; Patch LiteLLM and Langflow First8 min
  6. highAI SecurityLightLLM Visual Nodes Expose Unauthenticated Pickle RCE (CVE-2026-103395), With No Fix Yet6 min