CVE-2026-105741: Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{projectid}/install) allowed authenticated remote attackers to bypass the "local-only" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an attacker could make the server treat the request as originating from localhost, letting them write/overwrite an MCP client configuration file on the server's filesystem. This vulnerability is fixed in 1.10.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflowto a version that resolves this vulnerability.Fixed in 1.10.3
Event History
Frequently Asked Questions
Which deployments are exposed?
Langflow versions from 1.5.0 through 1.10.2 are affected. Version 1.10.3 fixes the issue.
What does an attacker need to exploit this?
The attacker must be authenticated and able to send a request to the MCP configuration installation endpoint. They can supply an X-Forwarded-For header set to 127.0.0.1 to bypass the endpoint's local-only restriction.
What is the impact of successful exploitation?
An attacker can write or overwrite an MCP client configuration file on the server's filesystem through the installation endpoint.