CVE-2026-105697: Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration

Published Oct 5, 2026
·
Updated

Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in bash -c "exec {command} ...". Any user able to reach the MCP server settings ("Settings → MCP Servers → Add MCP Server", POST/PATCH /api/v2/mcp/servers/{servername}) or to build a flow with the MCP Tools component could add a "server" whose command is an arbitrary OS command (touch, rm -rf, a reverse shell, ...). The command runs on the Langflow host as the Langflow process user as soon as Langflow tries to connect to the server (listing servers, loading tools, running the flow) — even when the UI then reports that the stdio server failed to start. With the default LANGFLOWAUTOLOGIN=true, GET /api/v1/autologin hands out a token without credentials, so on an exposed instance running the default configuration this is reachable without an account. AUTOLOGIN is documented as a development-only setting; with it disabled, any authenticated (non-admin) user can exploit it. This issue is fixed in Langflow 1.10.3, langflow-base 0.10.3, and lfx 1.10.3.

Affected Software

3 affected components
pypi/langflow<1.10.3
pypi/langflow-base<0.10.3
pypi/lfx<1.10.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Langflow to a version that resolves this vulnerability.

    Fixed in 1.10.3
  2. Upgrade

    Upgrade langflow-base to a version that resolves this vulnerability.

    Fixed in 0.10.3
  3. Upgrade

    Upgrade lfx to a version that resolves this vulnerability.

    Fixed in 1.10.3
  4. Configuration

    Disable LANGFLOW_AUTO_LOGIN; the setting is documented as development-only, and the default LANGFLOW_AUTO_LOGIN=true allows unauthenticated access to the auto-login endpoint.

    Langflow LANGFLOW_AUTO_LOGIN = false

Event History

Oct 5, 2026
CVE Published
via MITRE·08:16 PM
Data Sourced
via MITRE·08:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Are instances using the default configuration exposed without an account?

Yes. When LANGFLOW_AUTO_LOGIN=true, the default setting, the auto-login endpoint issues a token without credentials; an exposed instance can therefore be reached without an account. This setting is documented as development-only.

2

What access does an attacker need when auto-login is disabled?

Any authenticated user, including a non-admin user, can create or modify an MCP server configuration or build a flow using the MCP Tools component. No elevated administrative role is required.

3

When is the configured command executed?

It runs as the Langflow process user when Langflow attempts to connect to the configured server, such as while listing servers, loading tools, or running a flow. Execution can occur even if the UI reports that the stdio server failed to start.

4

What versions address the issue?

The issue is fixed in Langflow 1.10.3 and langflow-base 0.10.3. Disabling auto-login removes the unauthenticated access path, but does not prevent exploitation by authenticated non-admin users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203