DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105697: CVE-2026-105697: OS Command Injection in Langflow Model Context Protocol Integration

CVE-2026-105697: OS Command Injection in Langflow Model Context Protocol Integration

Vulnerability ID: CVE-2026-105697
CVSS Score: 9.9
Published: 2026-10-07

A critical OS command injection vulnerability exists in Langflow's Model Context Protocol (MCP) server integration using stdio transport, allowing unauthenticated remote command execution under default configurations.

TL;DR

Langflow versions prior to 1.10.3 allowed unauthenticated remote attackers to execute arbitrary shell commands on the hosting system by exploiting a model context protocol (MCP) server integration wrapper that parsed commands inside a shell context.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-78 (Improper Neutralization of Special Elements used in an OS Command)
  • Attack Vector: Network (AV:N)
  • CVSS Severity Score: 9.9 (Critical)
  • EPSS Score: 0.00396
  • Exploit Status: poc
  • KEV Status: Not Listed

Affected Systems

  • langflow
  • langflow-base
  • lfx
  • langflow: >= 1.1.2, < 1.10.3 (Fixed in: 1.10.3)
  • langflow-base: >= 0.1.2, < 0.10.3 (Fixed in: 0.10.3)
  • lfx: < 1.10.3 (Fixed in: 1.10.3)

Code Analysis

Commit: efbc4a1

Initial Pydantic schema validation implementation and command constraints.

Commit: eba285e

Centralized execution-level validation gate and shell-less subprocess configuration.

Exploit Details

  • GitHub Security Advisory: Advisory context detailing vulnerability mechanics, reproduction scenarios, and patched components.

Mitigation Strategies

  • Upgrade Langflow, langflow-base, and lfx to secure versions (>= 1.10.3 / >= 0.10.3)
  • Disable the development auto-login feature in production environments
  • Apply strict network firewall policies to restrict public access to port 7860

Remediation Steps:

  1. Step 1: Terminate current insecure Langflow container or system processes.
  2. Step 2: Update the requirement files or container images to target version 1.10.3.
  3. Step 3: Modify configuration settings, ensuring the environment variable LANGFLOW_AUTO_LOGIN is explicitly configured to false.
  4. Step 4: Restart the service and verify that the endpoint /api/v1/auto_login no longer issues authorization tokens without authentication.

References


Read the full report for CVE-2026-105697 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)