Impact
A flaw in Langflow allows authenticated users to define an MCP server with the Stdio transport, causing the supplied command field to be passed unmodified to the system shell. The command string is executed as a bash process with no validation, allowlisting, or sandboxing, giving the user the ability to run arbitrary operating‑system commands and inject environment variables such as LD_PRELOAD or PATH. This is a classic Process Control vulnerability (CWE-78) that can compromise confidentiality, integrity, and availability of the server.
Affected Systems
Version 1.9.0 and above mitigate the issue. Vulnerable instances are those running Langflow prior to version 1.9.0. The affected product is Langflow by langflow‑ai.
Risk and Exploitability
The CVSS score of 9.9 highlights the severity of the vulnerability. EPSS is not available, and the vulnerability is not listed in KEV, meaning there is no confirmed exploitation yet. The vulnerability is fixed in version 1.9.0, but for systems on earlier versions the immediacy of the command execution path makes this a high‑risk, exploitable flaw for any attacker who can obtain authenticated access to the application. The most plausible attack path is an authenticated user creating a malicious MCP server where the command is executed immediately upon the server list being fetched.
OpenCVE Enrichment