CRITICAL
9.9 CVE-2026-105740 Published 5 Oct 2026
Langflow Remote Code Execution Vulnerability
Worried this affects your website?
Langflow, a tool for building and deploying AI-powered agents and workflows, has a Remote Code Execution (RCE) vulnerability before version 1.9.0.
Any authenticated Langflow user can exploit it by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with zero validation, no allowlisting, and no sandboxing.
- The command executes immediately when the server list is fetched.
- The env field allows arbitrary environment variable injection (e.g., LD_PRELOAD, PATH override).
- This vulnerability is fixed in 1.9.0.
Reference: CVE-2026-105740 on NVD
← Back to Security News