Description
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the "local-only" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an attacker could make the server treat the request as originating from localhost, letting them write/overwrite an MCP client configuration file on the server's filesystem. This vulnerability is fixed in 1.10.3.
Published: 2026-10-05
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Remote Configuration Write
Action: Immediate Patch
AI Analysis

Impact

Langflow versions between 1.5.0 and 1.10.3 contain an IP‑spoofing flaw in the Model Context Protocol installation endpoint. By sending a forged X‑Forwarded‑For header that includes the loopback address, an attacker who authenticates to the application can cause the server to interpret the request as originating from localhost. The flaw allows the attacker to write or overwrite an MCP client configuration file on the server’s file system.

Affected Systems

The vulnerability affects installations of the langflow‑ai Langflow application from version 1.5.0 through 1.10.3. No other product versions or vendors are identified as affected.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity impact. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation is reported. An attacker must hold valid application credentials and must be able to craft HTTP requests; the exploit requires only the ability to set an HTTP header, which is trivial to do with common command‑line tools or proxy utilities. Exposure of the installation endpoint over the internet therefore poses a significant risk of unauthorized configuration changes.

Generated by OpenCVE AI on October 5, 2026 at 23:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch by upgrading Langflow to version 1.10.3 or later.
  • Remove or validate the X‑Forwarded‑For header at the reverse proxy or load balancer level so the server only receives trusted client IPs.
  • Limit access to the MCP installation endpoint to trusted internal networks or enforce mutual TLS with client certificates to reduce the attack surface.

Generated by OpenCVE AI on October 5, 2026 at 23:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the "local-only" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an attacker could make the server treat the request as originating from localhost, letting them write/overwrite an MCP client configuration file on the server's filesystem. This vulnerability is fixed in 1.10.3.
Title Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write
Weaknesses CWE-290
CWE-345
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T20:56:00.060Z

Reserved: 2026-10-05T19:11:07.946Z

Link: CVE-2026-105741

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T21:16:35.740

Modified: 2026-10-05T21:16:35.740

Link: CVE-2026-105741

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T23:45:18Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-345

    Insufficient Verification of Data Authenticity