SECURITYCRITICALCVE-2026-105740

CVE-2026-105740: Langflow Authenticated RCE via MCP Stdio Transport

Authenticated Langflow users could run arbitrary OS commands by adding a malicious MCP Stdio server; the command hit bash -c exec unsanitized.

Dylan H.

Security Team

October 6, 2026
5 min read
CVE-2026-105740: Langflow Authenticated RCE via MCP Stdio Transport

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Langflow before 1.9.0

Overview

A critical remote code execution vulnerability has been disclosed in Langflow, the open-source tool for building and deploying AI-powered agents and workflows. Tracked as CVE-2026-105740 with a maximum-severity CVSS score of 9.9, the flaw allows any authenticated Langflow user — not just administrators — to achieve full remote code execution on the server simply by adding a Model Context Protocol (MCP) server configured with the "Stdio" transport.

The root cause: the user-supplied command field on a new MCP server was passed directly into bash -c "exec {command}" with no validation, no allowlisting, and no sandboxing. Any shell metacharacters an attacker included were interpreted by the shell rather than treated as a literal program invocation.

This advisory covers the original disclosure, fixed in Langflow 1.9.0. A related, broader issue in the same MCP stdio execution path was later tracked separately as CVE-2026-105697 — see the Discovery & Disclosure section below for how the two connect.


Technical Details

FieldValue
CVE IDCVE-2026-105740
SeverityCritical (CVSS 9.9)
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWECWE-78 — Improper Neutralization of Special Elements used in an OS Command
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow (any authenticated user)
User InteractionNone
ImpactFull remote code execution on the Langflow host
Affected VersionsLangflow versions before 1.9.0 (confirmed in 1.8.3)
Fixed Version1.9.0

How It Works

Langflow's MCP integration lets a user register external MCP servers that Langflow then connects to as a client. For servers configured with the "Stdio" transport, Langflow spawns the server as a local subprocess communicating over standard input/output, using a command field (and an associated env map) supplied through the "Add MCP Server" UI and REST API.

Prior to 1.9.0, that command field was handed straight to a shell invocation equivalent to bash -c "exec {command}" — with zero validation, no command allowlist, and no sandboxing. Because the string was interpreted by bash, an attacker could embed shell metacharacters (;, |, &&, backticks, $()) to chain arbitrary commands rather than simply naming a program to run. The injected command executed automatically the moment Langflow tried to use the server — for example, as soon as the MCP server list was fetched or refreshed — requiring no further action from the attacker. The unsanitized env field compounded the issue, letting an attacker set variables such as LD_PRELOAD or override PATH to hijack execution of other processes on the host.

Langflow 1.9.0 fixed this by adding command allowlisting plus argument and environment-variable validation to the REST API model backing the "Add MCP Server" endpoint — closing off that specific creation path.


Impact Assessment

Who Is At Risk

  • Self-hosted Langflow deployments on versions before 1.9.0 (confirmed affected at 1.8.3) with more than one trusted user account, since any authenticated user — not only admins — could add MCP servers
  • Deployments where credentials are shared more widely than intended, or where lower-trust internal users hold valid accounts
  • Any Langflow instance whose host process has access to sensitive data, internal network segments, or cloud metadata endpoints, since RCE here converts directly into broader infrastructure compromise

Potential Attack Chains

  1. Authentication — Attacker obtains or already holds any valid Langflow account, even a low-privileged, non-admin one
  2. Malicious MCP Server — Attacker opens Settings → MCP Servers → Add MCP Server, selects the "Stdio" transport, and supplies a command field containing a shell one-liner (e.g., a reverse shell or a curl | bash download-and-execute chain)
  3. Automatic Execution — The command runs as soon as Langflow lists or loads the MCP server, inheriting the privileges of the Langflow process
  4. Post-Exploitation — Attacker pivots to host-level access, harvests environment secrets and configuration, or uses env injection (LD_PRELOAD/PATH) to persist across restarts

Mitigation

Immediate Actions

  • Upgrade to Langflow 1.9.0 or later immediately. Important: 1.9.0 alone closes only this specific vector — upgrade to 1.10.3 or later to also close the related, broader issue tracked as CVE-2026-105697
  • Audit existing MCP server configurations for unexpected "Stdio" transport entries or suspicious command/env values
  • Until patched, restrict which users can authenticate to the instance and avoid sharing credentials across trust boundaries

Detection Opportunities

  • Review Langflow API/audit logs for requests to MCP server configuration endpoints whose command field contains shell metacharacters (;, |, &&, backticks, $())
  • Monitor for unexpected bash -c child processes spawned by the Langflow server process
  • Watch for outbound connections or reverse-shell activity originating from Langflow hosts shortly after an MCP server configuration change

Defence-in-Depth

  • Run Langflow under least-privilege OS accounts and container isolation so a compromised process has minimal blast radius
  • Network-segment Langflow instances away from sensitive internal systems and cloud metadata endpoints
  • Where the deployment supports role-based restrictions, limit which users can configure MCP servers at all

Discovery & Disclosure

The vulnerability was reported by GitHub user AbdrrahimDahmani and is tracked upstream as GHSA-7w94-79vh-5mr2. It was fixed in Langflow 1.9.0 by PR #12290, which added command allowlisting and argument/environment-variable validation to the "Add MCP Server" REST model.

That fix, however, addressed only the creation endpoint. The same underlying bash -c "exec {command}" execution primitive remained reachable through other code paths — including MCP configurations embedded in flows and the server execution/connect boundary itself — until Langflow 1.10.3. That broader, regressed exposure is tracked separately as CVE-2026-105697. As of publication, CVE-2026-105740 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public proof-of-concept exploit has been observed.


References