CVE-2026-6599: langflow-ai langflow Model Context Protocol Configuration API mcp_projects.py install_mcp_config injection
A vulnerability was detected in langflow-ai langflow up to 1.8.3. The impacted element is the function getclientip/installmcpconfig of the file src/backend/base/langflow/api/v1/mcpprojects.py of the component Model Context Protocol Configuration API. Performing a manipulation of the argument X-Forwarded-For results in injection. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6599?
CVE-2026-6599 is classified as a medium severity vulnerability due to potential injection risks.
How do I fix CVE-2026-6599?
To fix CVE-2026-6599, upgrade langflow-ai langflow to version 1.8.4 or higher.
What systems are affected by CVE-2026-6599?
CVE-2026-6599 affects langflow-ai langflow versions up to 1.8.3.
What kind of injection is present in CVE-2026-6599?
CVE-2026-6599 allows for context protocol configuration injection through the install_mcp_config function.
What file contains the vulnerability in CVE-2026-6599?
The vulnerability in CVE-2026-6599 is located in the src/backend/base/langflow/api/v1/mcp_projects.py file.