Description
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files.
Published: 2026-07-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to execute arbitrary code on the server by bypassing the MCP server configuration validator due to incomplete validation enforcement on configuration files. This weakness is identified as CWE-20 (Impaired Input Validation) and could be introduced via the file upload API, potentially compromising confidentiality, integrity, and availability of the affected system.

Affected Systems

The vulnerability affects IBM Langflow OSS versions 1.0.0 through 1.10.0. Affected users should update to version 1.10.1 or later. The affected product is IBM Langflow OSS, an open‑source language model workflow tool.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity risk. The EPSS score of less than 1% indicates a low probability of exploitation, but the attack vector is likely through the file upload API, allowing an attacker to supply a crafted configuration file that is not properly validated. The vulnerability is not listed in the CISA KEV catalog, but the potential for remote code execution warrants prompt remediation.

Generated by OpenCVE AI on August 4, 2026 at 07:06 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.1 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.10.1 or a later supported release.
  • Temporarily disable or restrict the file upload API for MCP configuration files until the upgrade is applied.
  • Enforce strict server‑side validation of uploaded MCP configuration files, allowing only trusted parameters and rejecting any unexpected input.

Generated by OpenCVE AI on August 4, 2026 at 07:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Wed, 22 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Tue, 21 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Sat, 18 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files.
Title MCP Server Configuration Validator Bypass via File Upload API
First Time appeared Ibm
Ibm langflow Oss
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.10.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-23T03:56:09.818Z

Reserved: 2026-05-04T03:09:10.217Z

Link: CVE-2026-7755

cve-icon Vulnrichment

Updated: 2026-07-17T20:05:34.143Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T07:15:03Z

Weaknesses
  • CWE-20

    Improper Input Validation