Sceawere
Vulnerability Detail
CVE-2026-105697UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Langflow Remote Code Execution Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 2h ago
- Vendor
- langflow-ai
- Product
- langflow
- Attack Type
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in bash -c "exec {command} ...". Any user able to reach the MCP server settings ("Settings → MCP Servers → Add MCP Server", POST/PATCH /api/v2/mcp/servers/{server_name}) or to build a flow with the MCP Tools component could add a "server" whose command is an arbitrary OS command (touch, rm -rf, a reverse shell, ...). The command runs on the Langflow host as the Langflow process user as soon as Langflow tries to connect to the server (listing servers, loading tools, running the flow) — even when the UI then reports that the stdio server failed to start. With the default LANGFLOW_AUTO_LOGIN=true, GET /api/v1/auto_login hands out a token without credentials, so on an exposed instance running the default configuration this is reachable without an account. AUTO_LOGIN is documented as a development-only setting; with it disabled, any authenticated (non-admin) user can exploit it. This issue is fixed in Langflow 1.10.3, langflow-base 0.10.3, and lfx 1.10.3.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-10-05T21:16:35.087Z",
"pubdate": "2026-10-05T21:16:35.087Z",
"executiveSummary": "Langflow versions prior to 1.10.3 are susceptible to a critical Remote Code Execution (RCE) vulnerability stemming from improper input validation within the MCP (Model Context Protocol) stdio transport mechanism.\nThe vulnerability allows an unauthenticated or authenticated user to inject and execute arbitrary OS commands on the host running the Langflow process by defining malicious server configurations.\nThis flaw exists because the application failed to implement an allowlist for commands and executed provided input within a shell context using bash -c 'exec {command}'.\nIn configurations where LANGFLOW_AUTO_LOGIN is enabled, the vulnerability is reachable without authentication, significantly increasing the risk of unauthorized system access.\nThe impact includes full host compromise, potential data exfiltration, and lateral movement within the environment where the Langflow instance is deployed.\nExploitation is trivial, requiring only the ability to reach the MCP server configuration API endpoints or interact with the MCP Tools component in a flow.",
"technicalDetails": "The root cause of this vulnerability is the insecure handling of MCP server configurations within the Langflow application. Specifically, the MCP stdio transport implementation failed to validate or restrict the command and arguments provided by users when defining new MCP servers via the /api/v2/mcp/servers/{server_name} endpoints (POST/PATCH methods).\nPrior to version 1.10.3, the system wrapped the user-supplied command strings directly into a bash -c 'exec {command} ...' statement. This lack of sanitization or an allowlist mechanism allows an attacker to break out of the intended command context and execute arbitrary shell commands with the privileges of the Langflow service user.\nThe attack flow begins when an attacker submits a malicious payload via the MCP server settings or by configuring an MCP Tools component in a flow. Once the configuration is saved, the Langflow engine attempts to establish a connection to the defined MCP server. This connection attempt triggers the execution of the injected command on the host operating system.\nSignificantly, the vulnerability is triggered even if the UI reports a failure to start the stdio server, as the underlying process execution occurs prior to the connection validation. The shell execution happens synchronously or asynchronously as the Langflow process attempts to initialize the transport layer.\nThe exploitability of this vulnerability is exacerbated by the default LANGFLOW_AUTO_LOGIN=true setting. In this state, the /api/v1/auto_login endpoint issues a valid authentication token without requiring credentials, exposing the configuration APIs to unauthenticated network actors. Even when auto-login is disabled, any authenticated user with access to the dashboard can trigger the RCE.\nBecause the command is executed as the Langflow process user, the attacker inherits the system permissions assigned to that user. This allows for post-exploitation activities including, but not limited to, establishing a reverse shell, filesystem traversal, theft of environment variables or API keys, and deployment of persistence mechanisms on the host.\nThis flaw affects Langflow, langflow-base, and lfx versions prior to 1.10.3."
}