Sceawere

Vulnerability Detail

CVE-2026-105741UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Langflow MCP IP Spoofing Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
2h ago
Vendor
langflow-ai
Product
langflow
Attack Type
CWE-290: Authentication Bypass by Spoofing
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the "local-only" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an attacker could make the server treat the request as originating from localhost, letting them write/overwrite an MCP client configuration file on the server's filesystem. This vulnerability is fixed in 1.10.3.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-05T21:16:35.740Z",
  "pubdate": "2026-10-05T21:16:35.740Z",
  "executiveSummary": "Langflow versions 1.5.0 through 1.10.3 contain an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install).\nThe vulnerability stems from improper validation of the request origin, allowing authenticated remote attackers to bypass critical 'local-only' security restrictions.\nBy manipulating the X-Forwarded-For HTTP header to include '127.0.0.1', an attacker can trick the server-side logic into identifying the request as originating from the localhost environment.\nThis flaw facilitates unauthorized write or overwrite operations on MCP client configuration files stored on the server's filesystem.\nThe risk is significant as it allows an authenticated user to perform administrative file operations that are intended to be restricted to the local system environment, potentially leading to unauthorized system configuration changes or arbitrary file modification within the application's context.\nExploitation requires the attacker to hold valid authentication credentials for the Langflow instance to interact with the protected API endpoint.",
  "technicalDetails": "The vulnerability resides within the endpoint handling MCP project configurations: POST /api/v1/mcp/project/{project_id}/install. This component is designed to manage internal MCP client settings, which are subject to a restrictive security policy permitting modifications only when requests are verified as originating from the local loopback address (127.0.0.1).\nThe root cause is an insecure implementation of IP address verification. The server-side application logic relies on untrusted HTTP headers, specifically 'X-Forwarded-For', to determine the source IP of the incoming request. Because the application blindly trusts the value provided in this header without performing secondary validation or verifying the integrity of the proxy chain, it is susceptible to header spoofing.\nThe exploitation flow proceeds as follows: First, an authenticated attacker crafts a malicious POST request directed at the /api/v1/mcp/project/{project_id}/install endpoint. Second, the attacker inserts the 'X-Forwarded-For: 127.0.0.1' header into the HTTP request. Third, the Langflow server receives the request, inspects the spoofed header, and incorrectly asserts that the request originates from a local trusted source. Fourth, the server bypasses the 'local-only' access control checks, which would otherwise reject remote requests. Finally, the server executes the write operation, allowing the attacker to create or overwrite sensitive MCP client configuration files on the underlying filesystem.\nThe attack is effective because the trust boundary is improperly established based on client-supplied data rather than robust network-level information or cryptographically signed assertions. This vulnerability allows an authenticated attacker to manipulate critical system-level configuration files that govern how the Model Context Protocol connects to external or internal resources. By controlling these configurations, an attacker may redirect traffic, inject malicious MCP client parameters, or corrupt the application's configuration state, leading to further compromise of the agentic workflows built within Langflow. The flaw affects all instances running versions 1.5.0 through 1.10.3."
}
CVE-2026-105741: Langflow MCP IP Spoofing Vulnerability (HIGH Severity, CVSS: 7.1) | Sceawere