SECURITYCRITICALCVE-2026-105697

CVE-2026-105697: Langflow MCP Stdio RCE — Incomplete Fix Reopens Remote Code Execution

Langflow's 1.9.0 MCP Stdio RCE fix was incomplete — the same bash -c exec flaw stayed reachable until 1.10.3, which removed the shell entirely.

Dylan H.

Security Team

October 6, 2026
7 min read
CVE-2026-105697: Langflow MCP Stdio RCE — Incomplete Fix Reopens Remote Code Execution

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Langflow 1.1.2 through 1.10.2
  • langflow-base 0.1.2 through 0.10.2
  • lfx before 1.10.3

Overview

CVE-2026-105697 is the direct continuation of CVE-2026-105740, the earlier Langflow MCP "Stdio" transport remote code execution flaw. That first issue was fixed in Langflow 1.9.0 by adding command allowlisting and argument/environment-variable validation — but only at the REST API model backing the "Add MCP Server" creation endpoint. CVE-2026-105697 covers the discovery that the same unsanitized bash -c "exec {command}" execution primitive remained reachable through other code paths that the 1.9.0 patch never touched, leaving Langflow versions as recent as 1.10.2 still exploitable for remote code execution — including instances that had already "patched" for CVE-2026-105740.

Carrying the same maximum CVSS score of 9.9, this issue was only fully closed in Langflow 1.10.3, which validated the remaining execution boundaries (including MCP configurations embedded inside flows) and — structurally more important — removed the bash -c shell wrapper entirely, so the configured command is now spawned directly rather than interpreted by a shell.


Technical Details

FieldValue
CVE IDCVE-2026-105697
SeverityCritical (CVSS 9.9)
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWECWE-78 — Improper Neutralization of Special Elements used in an OS Command
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow (non-admin account) — none, if the instance runs with the dev-only LANGFLOW_AUTO_LOGIN setting enabled
User InteractionNone
ImpactFull remote code execution on the Langflow host
Affected Versionslangflow 1.1.2 through 1.10.2; langflow-base 0.1.2 through 0.10.2; lfx before 1.10.3
Fixed Versionslangflow 1.10.3; langflow-base 0.10.3; lfx 1.10.3

How It Works

The 1.9.0 fix for CVE-2026-105740 allowlisted commands only at the "Add MCP Server" REST endpoint — the specific creation flow a user exercises through Settings → MCP Servers. It did not validate the same command/args/env values when they reached the underlying spawn logic through other routes, including:

  • MCP "Stdio" server configurations embedded directly inside a flow definition (for example, via an MCP Tools component), rather than created through the guarded "Add MCP Server" UI/API path
  • The MCP server execution/connect boundary itself — the point where Langflow actually launches the configured subprocess when listing servers, loading tools, or running a flow — which called the same unsanitized bash -c "exec {command}" logic without passing back through the 1.9.0 allowlist
  • Final pre-fork execution boundaries that still assembled a shell command string from user-controlled input

In practice, this meant an attacker didn't need to use the now-validated "Add MCP Server" form at all: supplying a malicious stdio configuration through a flow, or hitting the server's execution/connect endpoint (tracked in threat-hunting guidance as POST/PATCH requests to /api/v2/mcp/servers/{server_name}), reached the exact same vulnerable code. The malicious command executes as soon as Langflow attempts to connect to the server — listing servers, loading tools, or running the flow — even if the UI subsequently reports that the stdio server "failed to start."

A second factor widens exposure further: LANGFLOW_AUTO_LOGIN is documented as a development-only convenience setting, but where it is left enabled in a running deployment, no credentials are required at all — exploitation becomes fully unauthenticated. With AUTO_LOGIN disabled (the recommended production posture), any authenticated non-admin account is sufficient.

Langflow 1.10.3 closed this completely by extending validation to these additional execution boundaries and, more fundamentally, removing the bash -c shell wrapper — the configured command/args now execute directly as a subprocess rather than being handed to a shell for interpretation, eliminating the shell-metacharacter injection class rather than merely filtering it.


Impact Assessment

Who Is At Risk

  • Langflow deployments running any version from 1.1.2 up to and including 1.10.2 — this explicitly includes instances that upgraded to 1.9.0 believing they had fully patched the earlier MCP stdio RCE
  • Deployments still running with LANGFLOW_AUTO_LOGIN enabled, which removes the authentication requirement entirely
  • Publicly reachable Langflow instances that expose the MCP server management API or allow flow import/execution from less-trusted users
  • Any organization that treated the 1.9.0 release as a complete fix for the MCP stdio RCE class and deprioritized further upgrades

Potential Attack Chains

  1. Recon — Attacker identifies an exposed Langflow instance on a version ≥ 1.1.2 and before 1.10.3, including versions that look "patched" because they are ≥ 1.9.0
  2. Access — If LANGFLOW_AUTO_LOGIN is enabled, no credentials are required at all; otherwise, any low-privileged authenticated account is sufficient
  3. Bypass of the 1.9.0 allowlist — Attacker reaches the vulnerable spawn logic through a path the earlier fix didn't cover: embedding a malicious MCP stdio server configuration inside a flow, or driving the execution/connect endpoint directly, instead of the now-guarded "Add MCP Server" creation endpoint
  4. Execution — The malicious command/args/env runs via the unsanitized bash -c "exec {command}" path as soon as Langflow attempts to connect to, list, or load the server — with full shell metacharacter interpretation
  5. Post-Exploitation — Full compromise of the host as the Langflow process user, lateral movement into connected networks, and theft of credentials/secrets from the runtime environment

Mitigation

Immediate Actions

  • Upgrade to Langflow 1.10.3, langflow-base 0.10.3, and lfx 1.10.3 or later — this is the only complete fix. If you previously upgraded only to 1.9.0 in response to CVE-2026-105740, you remain vulnerable to this issue and must upgrade again.
  • Set LANGFLOW_AUTO_LOGIN=false in any production deployment; it is a development-only setting and should never be left enabled on an internet- or network-reachable instance
  • Audit flow definitions (not just the MCP server list) for embedded MCP "Stdio" configurations with suspicious command or env values

Detection Opportunities

  • Inspect HTTP access logs for POST/PATCH requests to /api/v2/mcp/servers/{server_name} containing shell metacharacters or suspicious payloads (e.g., canary strings like touch /tmp/pwned)
  • Review imported/exported flow JSON for embedded MCP Tools components or stdio server configurations that weren't created through the standard "Add MCP Server" UI
  • Monitor for bash -c exec child processes spawned by Langflow worker processes, particularly around flow loads or tool-listing operations
  • Confirm LANGFLOW_AUTO_LOGIN is not set to true in any reachable environment

Defence-in-Depth

  • Pin Langflow (and langflow-base/lfx) to 1.10.3 or later, and track the subsequent 1.11.0 hardening release for further defense-in-depth improvements
  • Disable LANGFLOW_AUTO_LOGIN and enforce role-based access control on who may create or import flows and configure MCP servers
  • Run Langflow worker processes under least-privilege OS accounts and container/sandbox isolation — the 1.10.3 fix removes the shell wrapper but does not sandbox the executed binary itself
  • Network-segment Langflow instances away from sensitive internal systems and cloud metadata endpoints

Discovery & Disclosure

The issue was reported by MosesOX, with analysis by andifilhohub and remediation by erichare. It is tracked upstream as GHSA-w794-rj3p-xv45, which explicitly cross-references the earlier GHSA-7w94-79vh-5mr2 (CVE-2026-105740). The fix landed across multiple pull requests: #12290 (the 1.9.0 partial mitigation, now understood to be incomplete), #14036 (the 1.10.3 complete fix that removed the shell wrapper), and #13530 (additional 1.11.0 hardening). As of publication, CVE-2026-105697 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public proof-of-concept exploit has been observed.

Relationship to CVE-2026-105740: both advisories share the same root cause (CWE-78, OS command injection into the MCP stdio spawn path via bash -c "exec {command}") and the same maximum CVSS score of 9.9. CVE-2026-105740 covers the originally disclosed vector — the "Add MCP Server" creation endpoint — fixed on paper in Langflow 1.9.0. CVE-2026-105697 covers the broader set of execution boundaries the 1.9.0 fix did not reach, which kept the same underlying flaw exploitable through 1.10.2; it was only fully closed in 1.10.3 by validating those remaining boundaries and eliminating the shell wrapper altogether.


References