Listen to this Post
An IP spoofing vulnerability in Langflow’s Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allows authenticated remote attackers to bypass “local-only” access controls. The flaw exists inside the `get_client_ip` helper function located at src/backend/base/langflow/api/v1/mcp_projects.py. When a request reaches this helper, it inspects the HTTP headers for an `X-Forwarded-For` header. If present, `get_client_ip` parses the string, splits it by commas, and unconditionally takes the leftmost IP entry without verifying whether the request originated from a trusted proxy.
Because the client fully controls the leftmost entry of X-Forwarded-For, an attacker can inject 127.0.0.1. The application passes this value to is_local_ip(client_ip), which evaluates to True, allowing the request to bypass the local connection security gate. The endpoint then processes the incoming payload via `MCPInstallRequest` containing {client: str, transport: str | None}. Next, it calls `get_config_path(body.client)` to resolve a predefined, hardcoded file path relative to the server host’s home directory. Supported targets include `~/.cursor/mcp.json` for Cursor, `~/.codeium/windsurf/mcp_config.json` for Windsurf, or the Claude Desktop configuration file (~/Library/Application Support/Claude/claude_desktop_config.json on macOS or `%APPDATA%\Claude\claude_desktop_config.json` on Windows/WSL).
Although the attacker cannot write to arbitrary file paths on the filesystem, they can manipulate the configuration contents of these specific developer tools. Once an entry is injected or overwritten, any developer subsequently launching the affected IDE on the server host will connect to an attacker-controlled MCP server, resulting in potential supply chain compromise or service disruption.
DailyCVE Form:
Platform: Langflow
Version: >=1.5.0, <1.10.3
Vulnerability : IP Spoofing
Severity: High
date: 2026-10-05
Prediction: Already Patched
What Undercode Say
Analytics
Verify vulnerable helper in source code grep -A 10 "def get_client_ip" src/backend/base/langflow/api/v1/mcp_projects.py Check installed Langflow version pip show langflow | grep Version
Vulnerable code snippet
def get_client_ip(request: Request) -> str:
forwarded_for = request.headers.get("X-Forwarded-For")
if forwarded_for:
return forwarded_for.split(",")[bash].strip()
if request.client:
return request.client.host
return "255.255.255.255"
Exploit: (Educational Purposes!)
1. Obtain authentication bearer token and valid project_id
2. Send spoofed request to overwrite target client config
curl -X POST "http://<server-ip>:7860/api/v1/mcp/project/<project_id>/install" \
-H "Authorization: Bearer <token>" \
-H "X-Forwarded-For: 127.0.0.1" \
-H "Content-Type: application/json" \
-d '{"client": "cursor"}'
Protection:
Upgrade Langflow to version 1.10.3, 1.11.0, or higher. In patched versions, `get_client_ip` uses `request.client.host` by default and ignores `X-Forwarded-For` unless `rate_limit_trust_proxy` is explicitly enabled.
Impact:
Authenticated remote attackers can inject malicious MCP server configurations into developer IDE configuration files (Cursor, Windsurf, Claude Desktop) hosted on the server, potentially tricking local developers into connecting to untrusted external MCP endpoints.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

