PT-2026-106232 · Lfx+2 · Lfx+2

·

CVE-2026-105697

·

Published

2026-10-05

·

Updated

2026-10-06

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Langflow versions prior to 1.10.3 langflow-base versions prior to 0.10.3 lfx versions prior to 1.10.3
Description An issue exists in the MCP stdio transport where the software executes commands and arguments provided in an MCP server configuration without an allowlist. This allows a user to execute arbitrary OS commands on the host system as the process user. The flaw is accessible to users who can reach the MCP server settings via the UI or the POST/PATCH /api/v2/mcp/servers/{server name} endpoint, or those who can build a flow using the MCP Tools component. When the LANGFLOW AUTO LOGIN variable is set to true, the GET /api/v1/auto login endpoint provides a token without requiring credentials, potentially allowing unauthenticated access on exposed instances. If AUTO LOGIN is disabled, any authenticated non-admin user can still exploit this issue.
Recommendations Update Langflow to version 1.10.3. Update langflow-base to version 0.10.3. Update lfx to version 1.10.3. Disable the LANGFLOW AUTO LOGIN setting to prevent unauthenticated access.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105697

Affected Products

Langflow
Langflow-Base
Lfx