Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with zero validation, no allowlisting, and no sandboxing. The command executes immediately when the server list is fetched. Additionally, the env field allows arbitrary environment variable injection (e.g., LD_PRELOAD, PATH override). This vulnerability is fixed in 1.9.0.
Published: 2026-10-05
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in Langflow allows authenticated users to define an MCP server with the Stdio transport, causing the supplied command field to be passed unmodified to the system shell. The command string is executed as a bash process with no validation, allowlisting, or sandboxing, giving the user the ability to run arbitrary operating‑system commands and inject environment variables such as LD_PRELOAD or PATH. This is a classic Process Control vulnerability (CWE-78) that can compromise confidentiality, integrity, and availability of the server.

Affected Systems

Version 1.9.0 and above mitigate the issue. Vulnerable instances are those running Langflow prior to version 1.9.0. The affected product is Langflow by langflow‑ai.

Risk and Exploitability

The CVSS score of 9.9 highlights the severity of the vulnerability. EPSS is not available, and the vulnerability is not listed in KEV, meaning there is no confirmed exploitation yet. The vulnerability is fixed in version 1.9.0, but for systems on earlier versions the immediacy of the command execution path makes this a high‑risk, exploitable flaw for any attacker who can obtain authenticated access to the application. The most plausible attack path is an authenticated user creating a malicious MCP server where the command is executed immediately upon the server list being fetched.

Generated by OpenCVE AI on October 5, 2026 at 23:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Langflow to version 1.9.0 or later, which removes the unvalidated command execution path.
  • If an immediate upgrade is not possible, restrict user permissions so that only trusted administrators can add MCP servers with the Stdio transport, or completely disable that transport type.
  • Ensure all authenticated accounts follow least‑privilege principles to limit the impact should an attacker gain any valid credentials.

Generated by OpenCVE AI on October 5, 2026 at 23:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with zero validation, no allowlisting, and no sandboxing. The command executes immediately when the server list is fetched. Additionally, the env field allows arbitrary environment variable injection (e.g., LD_PRELOAD, PATH override). This vulnerability is fixed in 1.9.0.
Title Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T20:46:18.854Z

Reserved: 2026-10-05T19:11:07.946Z

Link: CVE-2026-105740

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T21:16:35.567

Modified: 2026-10-05T21:16:35.567

Link: CVE-2026-105740

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T23:15:19Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')