CVE-2026-105740
Received Received - Intake

Remote Code Execution in Langflow Prior to 1.9.0

Vulnerability report for CVE-2026-105740, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with zero validation, no allowlisting, and no sandboxing. The command executes immediately when the server list is fetched. Additionally, the env field allows arbitrary environment variable injection (e.g., LD_PRELOAD, PATH override). This vulnerability is fixed in 1.9.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
langflow-ai langflow < 1.9.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Langflow versions before 1.9.0 allow authenticated users to execute arbitrary commands on the server by configuring an MCP server with the Stdio transport. The command is passed directly to bash without validation or sandboxing, enabling Remote Code Execution (RCE). Additionally, environment variables can be manipulated to further escalate the attack.

Detection Guidance

Check Langflow version with 'pip show langflow' or 'langflow --version'. If version is below 1.9.0, the system is vulnerable. Inspect MCP server configurations for untrusted commands in the 'command' field or suspicious environment variables in the 'env' field.

Impact Analysis

An attacker with authenticated access could execute malicious commands on the server, leading to unauthorized data access, system compromise, or further network infiltration. This could result in data breaches, service disruption, or complete system takeover.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations may face legal penalties, reputational damage, and loss of compliance certifications.

Mitigation Strategies

Upgrade Langflow to version 1.9.0 or later immediately. Disable or remove any MCP servers with Stdio transport configured with untrusted commands. Review and restrict user permissions to prevent unauthorized MCP server additions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105740. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart