IP Spoofing Vulnerability in Langflow Tool by Langflow
CVE-2026-105741
7.1HIGH
What is CVE-2026-105741?
Langflow, a tool designed for developing AI-powered agents and workflows, has an IP spoofing vulnerability in the Model Context Protocol (MCP) installation endpoint. Versions 1.5.0 to 1.10.3 are affected, allowing authenticated remote attackers to exploit this weak point by spoofing an X-Forwarded-For header. This manipulation can enable attackers to bypass the designated 'local-only' access restriction, permitting unauthorized writing or overwriting of the MCP client configuration file on the server. This vulnerability was addressed in the 1.10.3 release.
Affected Version(s)
langflow >= 1.5.0, < 1.10.3
