CVE-2026-105740: Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with zero validation, no allowlisting, and no sandboxing. The command executes immediately when the server list is fetched. Additionally, the env field allows arbitrary environment variable injection (e.g., LDPRELOAD, PATH override). This vulnerability is fixed in 1.9.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflowto a version that resolves this vulnerability.Fixed in 1.9.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Langflow deployments running versions before 1.9.0 are affected if users can authenticate to the Langflow instance. Any authenticated user can trigger command execution on the server.
What does an attacker need to exploit this issue?
The attacker needs a valid Langflow account; no user interaction is required. They can add an MCP server using the Stdio transport and supply a command that is passed directly to bash.
When is the malicious command executed?
Execution occurs immediately when the MCP server list is fetched. This means the command does not need to wait for an agent or workflow to run.
Can environment variables also be manipulated?
Yes. The MCP server environment field permits arbitrary environment-variable injection, including values such as LD_PRELOAD or PATH overrides.
What is the available fix?
Upgrade Langflow to version 1.9.0, which fixes the vulnerability.