CVE-2026-105697: Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration
Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in bash -c "exec {command} ...". Any user able to reach the MCP server settings ("Settings → MCP Servers → Add MCP Server", POST/PATCH /api/v2/mcp/servers/{servername}) or to build a flow with the MCP Tools component could add a "server" whose command is an arbitrary OS command (touch, rm -rf, a reverse shell, ...). The command runs on the Langflow host as the Langflow process user as soon as Langflow tries to connect to the server (listing servers, loading tools, running the flow) — even when the UI then reports that the stdio server failed to start. With the default LANGFLOWAUTOLOGIN=true, GET /api/v1/autologin hands out a token without credentials, so on an exposed instance running the default configuration this is reachable without an account. AUTOLOGIN is documented as a development-only setting; with it disabled, any authenticated (non-admin) user can exploit it. This issue is fixed in Langflow 1.10.3, langflow-base 0.10.3, and lfx 1.10.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflowto a version that resolves this vulnerability.Fixed in 1.10.3 - Upgrade
Upgrade
langflow-baseto a version that resolves this vulnerability.Fixed in 0.10.3 - Upgrade
Upgrade
lfxto a version that resolves this vulnerability.Fixed in 1.10.3 - Configuration
Disable LANGFLOW_AUTO_LOGIN; the setting is documented as development-only, and the default LANGFLOW_AUTO_LOGIN=true allows unauthenticated access to the auto-login endpoint.
Langflow LANGFLOW_AUTO_LOGIN = false
Event History
Frequently Asked Questions
Are instances using the default configuration exposed without an account?
Yes. When LANGFLOW_AUTO_LOGIN=true, the default setting, the auto-login endpoint issues a token without credentials; an exposed instance can therefore be reached without an account. This setting is documented as development-only.
What access does an attacker need when auto-login is disabled?
Any authenticated user, including a non-admin user, can create or modify an MCP server configuration or build a flow using the MCP Tools component. No elevated administrative role is required.
When is the configured command executed?
It runs as the Langflow process user when Langflow attempts to connect to the configured server, such as while listing servers, loading tools, or running a flow. Execution can occur even if the UI reports that the stdio server failed to start.
What versions address the issue?
The issue is fixed in Langflow 1.10.3 and langflow-base 0.10.3. Disabling auto-login removes the unauthenticated access path, but does not prevent exploitation by authenticated non-admin users.