CVE-2026-105740: Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server

Published Oct 5, 2026
·
Updated

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with zero validation, no allowlisting, and no sandboxing. The command executes immediately when the server list is fetched. Additionally, the env field allows arbitrary environment variable injection (e.g., LDPRELOAD, PATH override). This vulnerability is fixed in 1.9.0.

Affected Software

1 affected component
Langflow Langflow<1.9.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Langflow to a version that resolves this vulnerability.

    Fixed in 1.9.0

Event History

Oct 5, 2026
CVE Published
via MITRE·08:46 PM
Data Sourced
via MITRE·08:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Langflow deployments running versions before 1.9.0 are affected if users can authenticate to the Langflow instance. Any authenticated user can trigger command execution on the server.

2

What does an attacker need to exploit this issue?

The attacker needs a valid Langflow account; no user interaction is required. They can add an MCP server using the Stdio transport and supply a command that is passed directly to bash.

3

When is the malicious command executed?

Execution occurs immediately when the MCP server list is fetched. This means the command does not need to wait for an agent or workflow to run.

4

Can environment variables also be manipulated?

Yes. The MCP server environment field permits arbitrary environment-variable injection, including values such as LD_PRELOAD or PATH overrides.

5

What is the available fix?

Upgrade Langflow to version 1.9.0, which fixes the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203