PT-2026-66519 · Langflow+2 · Langflow+1
CVE-2026-12940
·
Published
2026-07-30
·
Updated
2026-09-08
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Langflow OSS versions 1.0.0 through 1.10.1
Description
Unauthenticated remote code execution is possible via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The issue occurs in the
src/lfx/src/lfx/base/mcp/util.py file because the DANGEROUS ENV VARS blocklist does not include the SHELLOPTS, BASHOPTS, and PS4 environment variables.Recommendations
Update IBM Langflow OSS to a version later than 1.10.1.
Restrict the use of the MCP stdio launcher to minimize the risk of exploitation.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langflow
Langflow Oss