Sceawere
Vulnerability Detail
CVE-2026-105741UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Langflow MCP IP Spoofing Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 2h ago
- Vendor
- langflow-ai
- Product
- langflow
- Attack Type
- CWE-290: Authentication Bypass by Spoofing
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the "local-only" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an attacker could make the server treat the request as originating from localhost, letting them write/overwrite an MCP client configuration file on the server's filesystem. This vulnerability is fixed in 1.10.3.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-05T21:16:35.740Z",
"pubdate": "2026-10-05T21:16:35.740Z",
"executiveSummary": "Langflow versions 1.5.0 through 1.10.3 contain an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install).\nThe vulnerability stems from improper validation of the request origin, allowing authenticated remote attackers to bypass critical 'local-only' security restrictions.\nBy manipulating the X-Forwarded-For HTTP header to include '127.0.0.1', an attacker can trick the server-side logic into identifying the request as originating from the localhost environment.\nThis flaw facilitates unauthorized write or overwrite operations on MCP client configuration files stored on the server's filesystem.\nThe risk is significant as it allows an authenticated user to perform administrative file operations that are intended to be restricted to the local system environment, potentially leading to unauthorized system configuration changes or arbitrary file modification within the application's context.\nExploitation requires the attacker to hold valid authentication credentials for the Langflow instance to interact with the protected API endpoint.",
"technicalDetails": "The vulnerability resides within the endpoint handling MCP project configurations: POST /api/v1/mcp/project/{project_id}/install. This component is designed to manage internal MCP client settings, which are subject to a restrictive security policy permitting modifications only when requests are verified as originating from the local loopback address (127.0.0.1).\nThe root cause is an insecure implementation of IP address verification. The server-side application logic relies on untrusted HTTP headers, specifically 'X-Forwarded-For', to determine the source IP of the incoming request. Because the application blindly trusts the value provided in this header without performing secondary validation or verifying the integrity of the proxy chain, it is susceptible to header spoofing.\nThe exploitation flow proceeds as follows: First, an authenticated attacker crafts a malicious POST request directed at the /api/v1/mcp/project/{project_id}/install endpoint. Second, the attacker inserts the 'X-Forwarded-For: 127.0.0.1' header into the HTTP request. Third, the Langflow server receives the request, inspects the spoofed header, and incorrectly asserts that the request originates from a local trusted source. Fourth, the server bypasses the 'local-only' access control checks, which would otherwise reject remote requests. Finally, the server executes the write operation, allowing the attacker to create or overwrite sensitive MCP client configuration files on the underlying filesystem.\nThe attack is effective because the trust boundary is improperly established based on client-supplied data rather than robust network-level information or cryptographically signed assertions. This vulnerability allows an authenticated attacker to manipulate critical system-level configuration files that govern how the Model Context Protocol connects to external or internal resources. By controlling these configurations, an attacker may redirect traffic, inject malicious MCP client parameters, or corrupt the application's configuration state, leading to further compromise of the agentic workflows built within Langflow. The flaw affects all instances running versions 1.5.0 through 1.10.3."
}