Overview
A critical remote code execution vulnerability has been disclosed in Langflow, the open-source tool for building and deploying AI-powered agents and workflows. Tracked as CVE-2026-105740 with a maximum-severity CVSS score of 9.9, the flaw allows any authenticated Langflow user — not just administrators — to achieve full remote code execution on the server simply by adding a Model Context Protocol (MCP) server configured with the "Stdio" transport.
The root cause: the user-supplied command field on a new MCP server was passed directly into bash -c "exec {command}" with no validation, no allowlisting, and no sandboxing. Any shell metacharacters an attacker included were interpreted by the shell rather than treated as a literal program invocation.
This advisory covers the original disclosure, fixed in Langflow 1.9.0. A related, broader issue in the same MCP stdio execution path was later tracked separately as CVE-2026-105697 — see the Discovery & Disclosure section below for how the two connect.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-105740 |
| Severity | Critical (CVSS 9.9) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| CWE | CWE-78 — Improper Neutralization of Special Elements used in an OS Command |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | Low (any authenticated user) |
| User Interaction | None |
| Impact | Full remote code execution on the Langflow host |
| Affected Versions | Langflow versions before 1.9.0 (confirmed in 1.8.3) |
| Fixed Version | 1.9.0 |
How It Works
Langflow's MCP integration lets a user register external MCP servers that Langflow then connects to as a client. For servers configured with the "Stdio" transport, Langflow spawns the server as a local subprocess communicating over standard input/output, using a command field (and an associated env map) supplied through the "Add MCP Server" UI and REST API.
Prior to 1.9.0, that command field was handed straight to a shell invocation equivalent to bash -c "exec {command}" — with zero validation, no command allowlist, and no sandboxing. Because the string was interpreted by bash, an attacker could embed shell metacharacters (;, |, &&, backticks, $()) to chain arbitrary commands rather than simply naming a program to run. The injected command executed automatically the moment Langflow tried to use the server — for example, as soon as the MCP server list was fetched or refreshed — requiring no further action from the attacker. The unsanitized env field compounded the issue, letting an attacker set variables such as LD_PRELOAD or override PATH to hijack execution of other processes on the host.
Langflow 1.9.0 fixed this by adding command allowlisting plus argument and environment-variable validation to the REST API model backing the "Add MCP Server" endpoint — closing off that specific creation path.
Impact Assessment
Who Is At Risk
- Self-hosted Langflow deployments on versions before 1.9.0 (confirmed affected at 1.8.3) with more than one trusted user account, since any authenticated user — not only admins — could add MCP servers
- Deployments where credentials are shared more widely than intended, or where lower-trust internal users hold valid accounts
- Any Langflow instance whose host process has access to sensitive data, internal network segments, or cloud metadata endpoints, since RCE here converts directly into broader infrastructure compromise
Potential Attack Chains
- Authentication — Attacker obtains or already holds any valid Langflow account, even a low-privileged, non-admin one
- Malicious MCP Server — Attacker opens Settings → MCP Servers → Add MCP Server, selects the "Stdio" transport, and supplies a
commandfield containing a shell one-liner (e.g., a reverse shell or acurl | bashdownload-and-execute chain) - Automatic Execution — The command runs as soon as Langflow lists or loads the MCP server, inheriting the privileges of the Langflow process
- Post-Exploitation — Attacker pivots to host-level access, harvests environment secrets and configuration, or uses
envinjection (LD_PRELOAD/PATH) to persist across restarts
Mitigation
Immediate Actions
- Upgrade to Langflow 1.9.0 or later immediately. Important: 1.9.0 alone closes only this specific vector — upgrade to 1.10.3 or later to also close the related, broader issue tracked as CVE-2026-105697
- Audit existing MCP server configurations for unexpected "Stdio" transport entries or suspicious
command/envvalues - Until patched, restrict which users can authenticate to the instance and avoid sharing credentials across trust boundaries
Detection Opportunities
- Review Langflow API/audit logs for requests to MCP server configuration endpoints whose
commandfield contains shell metacharacters (;,|,&&, backticks,$()) - Monitor for unexpected
bash -cchild processes spawned by the Langflow server process - Watch for outbound connections or reverse-shell activity originating from Langflow hosts shortly after an MCP server configuration change
Defence-in-Depth
- Run Langflow under least-privilege OS accounts and container isolation so a compromised process has minimal blast radius
- Network-segment Langflow instances away from sensitive internal systems and cloud metadata endpoints
- Where the deployment supports role-based restrictions, limit which users can configure MCP servers at all
Discovery & Disclosure
The vulnerability was reported by GitHub user AbdrrahimDahmani and is tracked upstream as GHSA-7w94-79vh-5mr2. It was fixed in Langflow 1.9.0 by PR #12290, which added command allowlisting and argument/environment-variable validation to the "Add MCP Server" REST model.
That fix, however, addressed only the creation endpoint. The same underlying bash -c "exec {command}" execution primitive remained reachable through other code paths — including MCP configurations embedded in flows and the server execution/connect boundary itself — until Langflow 1.10.3. That broader, regressed exposure is tracked separately as CVE-2026-105697. As of publication, CVE-2026-105740 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public proof-of-concept exploit has been observed.