GHSA-4f6c-2vvp-gw82: High severity pip/langflow vulnerability

Published Oct 7, 2026
·
Updated

Description: Summary An IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{projectid}/install) allowed authenticated remote attackers to bypass the "local-only" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an attacker could make the server treat the request as originating from localhost, letting them write/overwrite an MCP client configuration file on the server's filesystem.

Details The vulnerability lived in the getclientip helper, used to enforce the local-only gate for installmcpconfig. It trusted the leftmost (fully client-controlled) entry of X-Forwarded-For unconditionally, with no check for whether the request had actually passed through a trusted proxy.

Vulnerable code (introduced by commit d3d06be8e5, first released in v1.5.0): src/backend/base/langflow/api/v1/mcpprojects.py

python def getclientip(request: Request) -> str: # Check for X-Forwarded-For header (common when behind proxies) forwardedfor = request.headers.get("X-Forwarded-For") if forwardedfor: # The client IP is the first one in the list return forwardedfor.split(",")[0].strip() if request.client: return request.client.host return "255.255.255.255"

@router.post("/{projectid}/install") async def installmcpconfig( projectid: UUID, body: MCPInstallRequest, # {client: str, transport: "sse" | "streamablehttp" | None} request: Request, currentuser: CurrentActiveMCPUser, ): clientip = getclientip(request) if not islocalip(clientip): raise HTTPException(statuscode=500, detail="MCP configuration can only be installed from a local connection") ...

Correction vs. the original report: the request body accepted by this endpoint is MCPInstallRequest {client: str, transport: str | None} (src/backend/base/langflow/api/v1/schemas/init.py). There is no mcppath field, and the destination path is never attacker-supplied. installmcpconfig resolves the write target itself, via getconfigpath(body.client), to one of a fixed, small set of well-known per-OS developer-tool config paths under the server process's home directory: ~/.cursor/mcp.json (Cursor), ~/.codeium/windsurf/mcpconfig.json (Windsurf), or the Claude Desktop config (~/Library/Application Support/Claude/claudedesktopconfig.json on macOS, %APPDATA%\Claude\claudedesktopconfig.json on Windows/WSL). The impact is therefore "attacker-influenced content written into one of these fixed files," not an arbitrary-path write.

PoC 1. Authenticate to obtain a valid access token. 2. Identify a projectid the attacker has access to. 3. Send: bash curl -X POST "http://<server-ip>:7860/api/v1/mcp/project/<projectid>/install" \ -H "Authorization: Bearer <token>" \ -H "X-Forwarded-For: 127.0.0.1" \ -H "Content-Type: application/json" \ -d '{"client": "cursor"}' 4. The server returns 200 OK and writes/overwrites ~/.cursor/mcp.json on the host with an attacker-influenced MCP server entry, despite the request originating from a remote, non-local address.

Impact Authenticated Remote Configuration Write to one of a fixed set of IDE/MCP client config files on the host. Could be leveraged to: - Inject a malicious MCP server definition into Cursor/Windsurf/Claude Desktop config, so a local developer who later opens that IDE on the host connects to an attacker-controlled MCP server. - Disrupt or corrupt the existing MCP configuration for those tools. - Bypass an intended network-boundary control ("local-only").

Status: already fixed This exact bypass (single-line, comma-separated X-Forwarded-For spoofing, default configuration) is fixed as of: - Fix PR: langflow-ai/langflow#13915 — "fix(security): stop trusting X-Forwarded-For for the MCP install locality check", landed as part of the broader hardening effort in langflow-ai/langflow#13530. - Fix: getclientip now uses the real TCP peer (request.client.host) by default and ignores X-Forwarded-For entirely unless the operator has explicitly opted in via the ratelimittrustproxy setting (default False); when opted in, it takes the rightmost entry, mirroring langflow.services.ratelimit.service.getclientip. - Released in: v1.11.0, and backported to v1.10.3 (langflow-ai/langflow#14071). - Related follow-up: a narrower, related bypass — reachable only when an operator has explicitly set ratelimittrustproxy=true behind a proxy that emits X-Forwarded-For as repeated header lines rather than a single comma-separated line (e.g. HAProxy's option forwardfor) — was separately closed by langflow-ai/langflow#14425, released in v1.11.3. This does not affect default deployments (ratelimittrustproxy defaults to False). - This report is a near-duplicate of GHSA-qvvj-g573-9638, which describes the same root cause and is fixed by the same PR.

Affected versions - The vulnerable endpoint/helper was introduced in v1.5.0 (langflow-ai/langflow#8271, "add one click install to mcp servers on specific clients", 2025-07-08). Versions prior to v1.5.0 do not contain this endpoint and are not affected by this issue. - Vulnerable: >= 1.5.0, < 1.10.3 (and < 1.11.0 on mainline). - Fixed: v1.10.3 (backport) and v1.11.0 onward.

Affected Software

1 affected componentFixes available
pip/langflow>=1.5.0<1.10.3
1.10.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/langflow to a version that resolves this vulnerability.

    Fixed in 1.10.3
  2. Upgrade

    Upgrade langflow to a version that resolves this vulnerability.

    Fixed in 1.10.3
  3. Configuration

    Keep rate_limit_trust_proxy disabled (False) unless proxy trust is explicitly required.

    Langflow rate_limit_trust_proxy = False

Event History

Oct 7, 2026
Advisory Published
via GitHub·04:18 PM
Data Sourced
via GitHub·04:18 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What access does an attacker need?

The attacker must be authenticated and able to send requests to the MCP configuration installation endpoint. No user interaction is required.

2

Which systems are exposed to remote exploitation?

Systems where an authenticated remote user can reach the installation endpoint are exposed because the local-only check can be bypassed with a client-controlled X-Forwarded-For header. The attacker can claim 127.0.0.1 as the originating address.

3

What is the practical impact of a successful attack?

An attacker can write or overwrite an MCP client configuration file on the server filesystem. This affects configuration integrity and may also have limited availability impact.

4

What is the earliest known affected release?

The vulnerable code was first released in v1.5.0. The provided data does not identify a fixed release version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203