Impact
Langflow versions between 1.5.0 and 1.10.3 contain an IP‑spoofing flaw in the Model Context Protocol installation endpoint. By sending a forged X‑Forwarded‑For header that includes the loopback address, an attacker who authenticates to the application can cause the server to interpret the request as originating from localhost. The flaw allows the attacker to write or overwrite an MCP client configuration file on the server’s file system.
Affected Systems
The vulnerability affects installations of the langflow‑ai Langflow application from version 1.5.0 through 1.10.3. No other product versions or vendors are identified as affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity impact. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation is reported. An attacker must hold valid application credentials and must be able to craft HTTP requests; the exploit requires only the ability to set an HTTP header, which is trivial to do with common command‑line tools or proxy utilities. Exposure of the installation endpoint over the internet therefore poses a significant risk of unauthorized configuration changes.
OpenCVE Enrichment