← Back to CVE List
CVE-2026-105740NVD
Vulnerability Summary
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with zero validation, no allowlisting, and no sandboxing. The command executes immediately when the server list is fetched. Additionally, the env field allows arbitrary environment variable injection (e.g., LD_PRELOAD, PATH override). This vulnerability is fixed in 1.9.0.
CVSS v3.1 Base Metrics — Score 9.9 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
Not provided by NVD for this CVE.
Not provided by NVD for this CVE.
External References
- https://github.com/langflow-ai/langflow/commit/efbc4a16e639409d938a4883463d27ef0bc637a0
- https://github.com/langflow-ai/langflow/pull/12290
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-7w94-79vh-5mr2
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-w794-rj3p-xv45
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-7w94-79vh-5mr2
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-w794-rj3p-xv45