CVE-2026-105741
Received Received - Intake

IP Spoofing in Langflow MCP Configuration

Vulnerability report for CVE-2026-105741, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the "local-only" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an attacker could make the server treat the request as originating from localhost, letting them write/overwrite an MCP client configuration file on the server's filesystem. This vulnerability is fixed in 1.10.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
langflow-ai langflow >= 1.5.0, < 1.10.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Langflow is a tool for building AI-powered agents. Between versions 1.5.0 and 1.10.3, it had an IP spoofing vulnerability in the MCP configuration installation endpoint. Attackers could bypass local-only restrictions by sending a spoofed X-Forwarded-For: 127.0.0.1 header, tricking the server into treating requests as coming from localhost. This allowed writing or overwriting MCP client configuration files on the server's filesystem.

Detection Guidance

Check Langflow server logs for POST requests to /api/v1/mcp/project/{project_id}/install with X-Forwarded-For: 127.0.0.1 headers. Inspect filesystem for unexpected MCP client configuration files in Langflow directories.

Impact Analysis

An authenticated remote attacker could exploit this to modify server configuration files, potentially leading to unauthorized access, data breaches, or disruption of AI workflows. The impact includes file system manipulation and potential privilege escalation on the server.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating confidentiality requirements in GDPR and HIPAA. It may result in non-compliance due to potential exposure of sensitive data or unauthorized system modifications.

Mitigation Strategies

Upgrade Langflow to version 1.10.3 or later. Review and remove any unauthorized MCP client configuration files. Monitor for suspicious POST requests to the vulnerable endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105741. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart