Arbitrary OS Command Execution Vulnerability in Langflow by Langflow AI
CVE-2026-105697

9.9CRITICAL

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-105697?

Langflow, a tool for building AI-powered agents and workflows, has a vulnerability that allows arbitrary OS command execution due to improper handling of MCP server configurations. Any user with access to the MCP server settings could insert malicious commands, which will be executed without restrictions when Langflow attempts to connect to the compromised server. The vulnerability also includes a default configuration that exposes the auto-login feature, potentially granting unauthorized access. This issue has been addressed in Langflow version 1.10.3 and subsequent releases.

Affected Version(s)

langflow >= 1.1.2, < 1.10.3

langflow-base >= 0.1.2, < 0.10.3

lfx < 1.10.3

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.