PT-2026-106232 · Lfx+2 · Lfx+2
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Langflow versions prior to 1.10.3
langflow-base versions prior to 0.10.3
lfx versions prior to 1.10.3
Description
An issue exists in the MCP stdio transport where the software executes commands and arguments provided in an MCP server configuration without an allowlist. This allows a user to execute arbitrary OS commands on the host system as the process user. The flaw is accessible to users who can reach the MCP server settings via the UI or the
POST/PATCH /api/v2/mcp/servers/{server name} endpoint, or those who can build a flow using the MCP Tools component. When the LANGFLOW AUTO LOGIN variable is set to true, the GET /api/v1/auto login endpoint provides a token without requiring credentials, potentially allowing unauthenticated access on exposed instances. If AUTO LOGIN is disabled, any authenticated non-admin user can still exploit this issue.Recommendations
Update Langflow to version 1.10.3.
Update langflow-base to version 0.10.3.
Update lfx to version 1.10.3.
Disable the
LANGFLOW AUTO LOGIN setting to prevent unauthenticated access.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langflow
Langflow-Base
Lfx