Langflow MCP Stdio Flaws Give Any Logged-In User a Shell: CVE-2026-105697 and CVE-2026-105740
Two CVSS 9.9 command-injection flaws in Langflow's MCP stdio transport let a low-privileged user run host commands. Fixed in 1.10.3; no exploitation reported.
· 5 min