Sceawere

Vulnerability Detail

CVE-2026-105740UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Langflow Remote Code Execution Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
2h ago
Vendor
langflow-ai
Product
langflow
Attack Type
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with zero validation, no allowlisting, and no sandboxing. The command executes immediately when the server list is fetched. Additionally, the env field allows arbitrary environment variable injection (e.g., LD_PRELOAD, PATH override). This vulnerability is fixed in 1.9.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-10-05T21:16:35.567Z",
  "pubdate": "2026-10-05T21:16:35.567Z",
  "executiveSummary": "A critical Remote Code Execution (RCE) vulnerability exists in Langflow versions prior to 1.9.0, stemming from improper input validation within the MCP server configuration component.\nThe vulnerability allows an authenticated attacker to execute arbitrary commands on the host server with the privileges of the Langflow service. By leveraging the 'Stdio' transport mechanism, an attacker can supply malicious commands and environment variables that are processed without sanitization or sandboxing.\nThe risk is categorized as critical because it facilitates full system compromise, data exfiltration, and potential lateral movement within the infrastructure. Exploitation requires authenticated access to the Langflow instance, but does not necessitate advanced privileges beyond standard user access, assuming the user can configure MCP servers.\nThe vulnerability manifests through direct injection into a system shell command execution flow, specifically bypassing intended security boundaries by failing to implement allowlisting or execution isolation.\nThe issue is fully remediated in Langflow version 1.9.0.",
  "technicalDetails": "The vulnerability resides in the MCP server configuration module of Langflow, specifically within the handling of the 'Stdio' transport transport type. The root cause is the unsafe pass-through of user-provided input strings directly into a shell execution context.\nWhen a user defines an MCP server using the 'Stdio' transport, the application captures a 'command' field. This field is subsequently utilized as a direct argument to a bash -c invocation, specifically formatted as bash -c \"exec {command}\". Because there is no input validation, sanitization, or command allowlisting performed on the input string, an attacker can inject arbitrary shell metacharacters (e.g., ;, &&, ||, or command substitution) to escape the intended command context and execute secondary malicious payloads.\nFurthermore, the vulnerability is exacerbated by an insecure 'env' field configuration. This field permits users to inject arbitrary environment variables into the process execution environment. An attacker can manipulate environment variables such as LD_PRELOAD to achieve library hijacking or modify PATH to redirect binary resolutions, thereby further weaponizing the RCE primitive.\nThe attack flow follows a predictable pattern: 1) The authenticated attacker navigates to the MCP server configuration interface. 2) The attacker defines a new MCP server specifying the 'Stdio' transport. 3) The attacker inputs an arbitrary command (e.g., reverse shell payload) in the 'command' field and malicious environment variables in the 'env' field. 4) The vulnerability triggers immediately upon the server list being fetched or refreshed, as the Langflow backend initiates the execution of the configured command to verify or establish the Stdio connection.\nBecause the execution occurs with the privileges of the Langflow service process, the attacker inherits the ability to read, modify, or delete files accessible to the service, execute arbitrary system binaries, and interact with the host network stack. There is no sandboxing or containerization enforced on these commands, meaning the exploit operates directly within the primary host environment. This represents a complete bypass of application-level access controls, effectively granting the attacker the same operational capability as the Langflow service user."
}
CVE-2026-105740: Langflow Remote Code Execution Vulnerability (CRITICAL Severity, CVSS: 9.9) | Sceawere