Overview
CVE-2026-105697 is the direct continuation of CVE-2026-105740, the earlier Langflow MCP "Stdio" transport remote code execution flaw. That first issue was fixed in Langflow 1.9.0 by adding command allowlisting and argument/environment-variable validation — but only at the REST API model backing the "Add MCP Server" creation endpoint. CVE-2026-105697 covers the discovery that the same unsanitized bash -c "exec {command}" execution primitive remained reachable through other code paths that the 1.9.0 patch never touched, leaving Langflow versions as recent as 1.10.2 still exploitable for remote code execution — including instances that had already "patched" for CVE-2026-105740.
Carrying the same maximum CVSS score of 9.9, this issue was only fully closed in Langflow 1.10.3, which validated the remaining execution boundaries (including MCP configurations embedded inside flows) and — structurally more important — removed the bash -c shell wrapper entirely, so the configured command is now spawned directly rather than interpreted by a shell.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-105697 |
| Severity | Critical (CVSS 9.9) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| CWE | CWE-78 — Improper Neutralization of Special Elements used in an OS Command |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | Low (non-admin account) — none, if the instance runs with the dev-only LANGFLOW_AUTO_LOGIN setting enabled |
| User Interaction | None |
| Impact | Full remote code execution on the Langflow host |
| Affected Versions | langflow 1.1.2 through 1.10.2; langflow-base 0.1.2 through 0.10.2; lfx before 1.10.3 |
| Fixed Versions | langflow 1.10.3; langflow-base 0.10.3; lfx 1.10.3 |
How It Works
The 1.9.0 fix for CVE-2026-105740 allowlisted commands only at the "Add MCP Server" REST endpoint — the specific creation flow a user exercises through Settings → MCP Servers. It did not validate the same command/args/env values when they reached the underlying spawn logic through other routes, including:
- MCP "Stdio" server configurations embedded directly inside a flow definition (for example, via an MCP Tools component), rather than created through the guarded "Add MCP Server" UI/API path
- The MCP server execution/connect boundary itself — the point where Langflow actually launches the configured subprocess when listing servers, loading tools, or running a flow — which called the same unsanitized
bash -c "exec {command}"logic without passing back through the 1.9.0 allowlist - Final pre-fork execution boundaries that still assembled a shell command string from user-controlled input
In practice, this meant an attacker didn't need to use the now-validated "Add MCP Server" form at all: supplying a malicious stdio configuration through a flow, or hitting the server's execution/connect endpoint (tracked in threat-hunting guidance as POST/PATCH requests to /api/v2/mcp/servers/{server_name}), reached the exact same vulnerable code. The malicious command executes as soon as Langflow attempts to connect to the server — listing servers, loading tools, or running the flow — even if the UI subsequently reports that the stdio server "failed to start."
A second factor widens exposure further: LANGFLOW_AUTO_LOGIN is documented as a development-only convenience setting, but where it is left enabled in a running deployment, no credentials are required at all — exploitation becomes fully unauthenticated. With AUTO_LOGIN disabled (the recommended production posture), any authenticated non-admin account is sufficient.
Langflow 1.10.3 closed this completely by extending validation to these additional execution boundaries and, more fundamentally, removing the bash -c shell wrapper — the configured command/args now execute directly as a subprocess rather than being handed to a shell for interpretation, eliminating the shell-metacharacter injection class rather than merely filtering it.
Impact Assessment
Who Is At Risk
- Langflow deployments running any version from 1.1.2 up to and including 1.10.2 — this explicitly includes instances that upgraded to 1.9.0 believing they had fully patched the earlier MCP stdio RCE
- Deployments still running with
LANGFLOW_AUTO_LOGINenabled, which removes the authentication requirement entirely - Publicly reachable Langflow instances that expose the MCP server management API or allow flow import/execution from less-trusted users
- Any organization that treated the 1.9.0 release as a complete fix for the MCP stdio RCE class and deprioritized further upgrades
Potential Attack Chains
- Recon — Attacker identifies an exposed Langflow instance on a version ≥ 1.1.2 and before 1.10.3, including versions that look "patched" because they are ≥ 1.9.0
- Access — If
LANGFLOW_AUTO_LOGINis enabled, no credentials are required at all; otherwise, any low-privileged authenticated account is sufficient - Bypass of the 1.9.0 allowlist — Attacker reaches the vulnerable spawn logic through a path the earlier fix didn't cover: embedding a malicious MCP stdio server configuration inside a flow, or driving the execution/connect endpoint directly, instead of the now-guarded "Add MCP Server" creation endpoint
- Execution — The malicious
command/args/envruns via the unsanitizedbash -c "exec {command}"path as soon as Langflow attempts to connect to, list, or load the server — with full shell metacharacter interpretation - Post-Exploitation — Full compromise of the host as the Langflow process user, lateral movement into connected networks, and theft of credentials/secrets from the runtime environment
Mitigation
Immediate Actions
- Upgrade to Langflow 1.10.3, langflow-base 0.10.3, and lfx 1.10.3 or later — this is the only complete fix. If you previously upgraded only to 1.9.0 in response to CVE-2026-105740, you remain vulnerable to this issue and must upgrade again.
- Set
LANGFLOW_AUTO_LOGIN=falsein any production deployment; it is a development-only setting and should never be left enabled on an internet- or network-reachable instance - Audit flow definitions (not just the MCP server list) for embedded MCP "Stdio" configurations with suspicious
commandorenvvalues
Detection Opportunities
- Inspect HTTP access logs for
POST/PATCHrequests to/api/v2/mcp/servers/{server_name}containing shell metacharacters or suspicious payloads (e.g., canary strings liketouch /tmp/pwned) - Review imported/exported flow JSON for embedded MCP Tools components or stdio server configurations that weren't created through the standard "Add MCP Server" UI
- Monitor for
bash -c execchild processes spawned by Langflow worker processes, particularly around flow loads or tool-listing operations - Confirm
LANGFLOW_AUTO_LOGINis not set totruein any reachable environment
Defence-in-Depth
- Pin Langflow (and
langflow-base/lfx) to 1.10.3 or later, and track the subsequent 1.11.0 hardening release for further defense-in-depth improvements - Disable
LANGFLOW_AUTO_LOGINand enforce role-based access control on who may create or import flows and configure MCP servers - Run Langflow worker processes under least-privilege OS accounts and container/sandbox isolation — the 1.10.3 fix removes the shell wrapper but does not sandbox the executed binary itself
- Network-segment Langflow instances away from sensitive internal systems and cloud metadata endpoints
Discovery & Disclosure
The issue was reported by MosesOX, with analysis by andifilhohub and remediation by erichare. It is tracked upstream as GHSA-w794-rj3p-xv45, which explicitly cross-references the earlier GHSA-7w94-79vh-5mr2 (CVE-2026-105740). The fix landed across multiple pull requests: #12290 (the 1.9.0 partial mitigation, now understood to be incomplete), #14036 (the 1.10.3 complete fix that removed the shell wrapper), and #13530 (additional 1.11.0 hardening). As of publication, CVE-2026-105697 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public proof-of-concept exploit has been observed.
Relationship to CVE-2026-105740: both advisories share the same root cause (CWE-78, OS command injection into the MCP stdio spawn path via bash -c "exec {command}") and the same maximum CVSS score of 9.9. CVE-2026-105740 covers the originally disclosed vector — the "Add MCP Server" creation endpoint — fixed on paper in Langflow 1.9.0. CVE-2026-105697 covers the broader set of execution boundaries the 1.9.0 fix did not reach, which kept the same underlying flaw exploitable through 1.10.2; it was only fully closed in 1.10.3 by validating those remaining boundaries and eliminating the shell wrapper altogether.
References
- NVD — CVE-2026-105697
- GitHub Security Advisory — GHSA-w794-rj3p-xv45
- Strix — CVE-2026-105697: langflow OS Command Injection
- TheHackerWire — Langflow OS Command Injection Enables Unauthenticated Remote Code Execution
- Related advisory: CVE-2026-105740 — Langflow Authenticated RCE via MCP Stdio Transport