CVE-2026-17623: Langflow is affected OS Command Injection in Model Context Protocol features
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in MCP server configurations.
Other sources
Langflow OSS could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in MCP server configurations.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17623?
The severity of CVE-2026-17623 is rated as high with a score of 8.8.
What type of vulnerability is CVE-2026-17623?
CVE-2026-17623 is classified as an OS Command Injection vulnerability.
Who can exploit CVE-2026-17623?
CVE-2026-17623 can be exploited by a remote authenticated attacker.
How do I fix CVE-2026-17623?
To fix CVE-2026-17623, ensure proper validation of the command field in MCP server configurations.
What software is affected by CVE-2026-17623?
CVE-2026-17623 affects IBM Langflow OSS versions 1.0.0 through 1.10.3.