CRITICAL 9.9 CVE-2026-105740 Published 5 Oct 2026

Langflow Remote Code Execution Vulnerability

Worried this affects your website?

Langflow, a tool for building and deploying AI-powered agents and workflows, has a Remote Code Execution (RCE) vulnerability before version 1.9.0.

Any authenticated Langflow user can exploit it by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with zero validation, no allowlisting, and no sandboxing.

  • The command executes immediately when the server list is fetched.
  • The env field allows arbitrary environment variable injection (e.g., LD_PRELOAD, PATH override).
  • This vulnerability is fixed in 1.9.0.

Reference: CVE-2026-105740 on NVD

← Back to Security News