Vulnerability
Published 2026-10-05
Verified 2026-10-06

Langflow CVE-2026-105697 / CVE-2026-105740 (CVSS 9.9): MCP stdio server config runs any OS command on the host, reachable without a login on default AUTO_LOGIN installs; plus CVE-2026-105741 X-Forwarded-For bypass — fully fixed in 1.10.3

CVE records published 5 October 2026 cover Langflow GitHub advisories on its Model Context Protocol (MCP) support. GHSA-w794-rj3p-xv45 (CVE-2026-105697, CVSS 3.1 9.9) and GHSA-7w94-79vh-5mr2 (CVE-2026-105740, 9.9) describe the same core flaw: when a user adds an MCP server with the stdio transport, or builds a flow with the MCP Tools component, Langflow launched the supplied command and arguments with no allowlist, wrapped in bash -c, so the command runs on the Langflow host as the Langflow process user as soon as Langflow connects to that server, even if the UI then says the server failed to start. The advisory notes that with the default LANGFLOW_AUTO_LOGIN=true, the auto-login endpoint hands out a token without credentials, so an exposed instance on the default setting can be exploited without an account; with auto-login off, any authenticated non-admin user can do it. The fix came in two steps: 1.9.0 added a command allowlist and argument/environment checks to the Add MCP Server API, and 1.10.3 applied the same policy at the point where the process is spawned (covering configs embedded in flows and tweaks) and removed the bash wrapper. A third advisory, GHSA-4f6c-2vvp-gw82 (CVE-2026-105741, 7.1), lets an authenticated user bypass the local-only check on the MCP config install endpoint by sending X-Forwarded-For: 127.0.0.1 and write an MCP client config file on the server (1.5.0 to before 1.10.3). The advisories do not report exploitation in the wild. Primary: Langflow GitHub security advisories; CVE records 5 Oct.

Product
Langflow (langflow, langflow-base and lfx PyPI packages; MCP server settings and MCP Tools component)
Versions
CVE-2026-105697: langflow 1.1.2 to before 1.10.3 (langflow-base 0.1.2 to before 0.10.3; lfx before 1.10.3). CVE-2026-105740: before 1.9.0. CVE-2026-105741: 1.5.0 to before 1.10.3. Fixed: langflow 1.10.3 / langflow-base 0.10.3 / lfx 1.10.3 or later.
CVSS
(CVSS 3.1, CVE-2026-105697 and CVE-2026-105740); 7.1 (CVE-2026-105741)
Exploited in Australia?
unknown
Patch to
Upgrade Langflow to 1.10.3 or later (current PyPI release is newer). Set LANGFLOW_AUTO_LOGIN=false on any instance reachable from a network, keep Langflow off the public internet or behind an authenticating proxy that strips client-supplied X-Forwarded-For, and review existing MCP server entries and flows for stdio commands you did not add.

Primary: Langflow GHSA-w794-rj3p-xv45 — OS command injection via MCP stdio server configuration (CVE-2026-105697) · Vendor: Langflow GHSA-7w94-79vh-5mr2 — Authenticated RCE via MCP stdio transport (CVE-2026-105740) · CVE: CVE-2026-105697, CVE-2026-105740, CVE-2026-105741 · Langflow GHSA-4f6c-2vvp-gw82 — X-Forwarded-For bypass allows remote MCP config write (CVE-2026-105741)

tech ai cloud