CRITICAL 9.9 CVE-2026-105697 Published 5 Oct 2026

Langflow MCP Server Configuration Command Injection Vulnerability

Worried this affects your website?

Langflow, a tool for building and deploying AI-powered agents and workflows, contains a command injection vulnerability in its MCP stdio transport before version 1.10.3.

The MCP stdio transport launches whatever command or arguments a user puts in an MCP server configuration, with no allowlist and, before 1.10.3, wrapped in bash -c "exec {command} ...". Any user who can reach the MCP server settings or build a flow with the MCP Tools component can add a "server" whose command is an arbitrary OS command such as touch, rm -rf, or a reverse shell. The command runs on the Langflow host as the Langflow process user as soon as Langflow tries to connect to the server, even if the UI reports that the stdio server failed to start.

  • Reachable via Settings → MCP Servers → Add MCP Server, POST/PATCH /api/v2/mcp/servers/{server_name}, or the MCP Tools component.
  • With default LANGFLOW_AUTO_LOGIN=true, GET /api/v1/auto_login hands out a token without credentials, making this exploitable without an account on an exposed instance.
  • AUTO_LOGIN is documented as development-only; with it disabled, any authenticated non-admin user can exploit it.
  • Fixed in Langflow 1.10.3, langflow-base 0.10.3, and lfx 1.10.3.

Reference: CVE-2026-105697 on NVD

← Back to Security News