Arbitrary OS Command Execution Vulnerability in Langflow by Langflow AI
CVE-2026-105697
9.9CRITICAL
What is CVE-2026-105697?
Langflow, a tool for building AI-powered agents and workflows, has a vulnerability that allows arbitrary OS command execution due to improper handling of MCP server configurations. Any user with access to the MCP server settings could insert malicious commands, which will be executed without restrictions when Langflow attempts to connect to the compromised server. The vulnerability also includes a default configuration that exposes the auto-login feature, potentially granting unauthorized access. This issue has been addressed in Langflow version 1.10.3 and subsequent releases.
Affected Version(s)
langflow >= 1.1.2, < 1.10.3
langflow-base >= 0.1.2, < 0.10.3
lfx < 1.10.3
