CVE-2026-105697: OS Command Injection in Langflow Model Context Protocol Integration
Vulnerability ID: CVE-2026-105697
CVSS Score: 9.9
Published: 2026-10-07
A critical OS command injection vulnerability exists in Langflow's Model Context Protocol (MCP) server integration using stdio transport, allowing unauthenticated remote command execution under default configurations.
TL;DR
Langflow versions prior to 1.10.3 allowed unauthenticated remote attackers to execute arbitrary shell commands on the hosting system by exploiting a model context protocol (MCP) server integration wrapper that parsed commands inside a shell context.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-78 (Improper Neutralization of Special Elements used in an OS Command)
- Attack Vector: Network (AV:N)
- CVSS Severity Score: 9.9 (Critical)
- EPSS Score: 0.00396
- Exploit Status: poc
- KEV Status: Not Listed
Affected Systems
- langflow
- langflow-base
- lfx
-
langflow: >= 1.1.2, < 1.10.3 (Fixed in:
1.10.3) -
langflow-base: >= 0.1.2, < 0.10.3 (Fixed in:
0.10.3) -
lfx: < 1.10.3 (Fixed in:
1.10.3)
Code Analysis
Commit: efbc4a1
Initial Pydantic schema validation implementation and command constraints.
Commit: eba285e
Centralized execution-level validation gate and shell-less subprocess configuration.
Exploit Details
- GitHub Security Advisory: Advisory context detailing vulnerability mechanics, reproduction scenarios, and patched components.
Mitigation Strategies
- Upgrade Langflow, langflow-base, and lfx to secure versions (>= 1.10.3 / >= 0.10.3)
- Disable the development auto-login feature in production environments
- Apply strict network firewall policies to restrict public access to port 7860
Remediation Steps:
- Step 1: Terminate current insecure Langflow container or system processes.
- Step 2: Update the requirement files or container images to target version 1.10.3.
- Step 3: Modify configuration settings, ensuring the environment variable LANGFLOW_AUTO_LOGIN is explicitly configured to false.
- Step 4: Restart the service and verify that the endpoint /api/v1/auto_login no longer issues authorization tokens without authentication.
References
- GitHub Security Advisory GHSA-w794-rj3p-xv45
- NVD Record for CVE-2026-105697
- Authoritative CVE Project Entry
- Langflow Release v1.10.3
Read the full report for CVE-2026-105697 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)