CVE-2026-105697

LOWCVSS 9.9 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in bash -c "exec {command} ...". Any user able to reach the MCP server settings ("Settings → MCP Servers → Add MCP Server", POST/PATCH /api/v2/mcp/servers/{server_name}) or to build a flow with the MCP Tools component could add a "server" whose command is an arbitrary OS command (touch, rm -rf, a reverse shell, ...). The command runs on the Langflow host as the Langflow process user as soon as Langflow tries to connect to the server (listing servers, loading tools, running the flow) — even when the UI then reports that the stdio server failed to start. With the default LANGFLOW_AUTO_LOGIN=true, GET /api/v1/auto_login hands out a token without credentials, so on an exposed instance running the default configuration this is reachable without an account. AUTO_LOGIN is documented as a development-only setting; with it disabled, any authenticated (non-admin) user can exploit it. This issue is fixed in Langflow 1.10.3, langflow-base 0.10.3, and lfx 1.10.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-10-06: 410-06
Referenced assets4 URLs
Full discourse4 posts
  • The Hacker Wire@TheHackerWire

    🚨 CVE-2026-105697 (CVSS 9.9 Critical) Langflow allows remote attackers to execute arbitrary OS commands through MCP Stdio server configs, reachable without auth via auto-login. https://www.thehackerwire.com/vulnerability/CVE-2026-105697/ https://t.co/91l5cVstrA

    0001038
    175 followersView on X
  • CVE@CVEnew

    CVE-2026-105697 Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a us… https://www.cve.org/CVERecord?id=CVE-2026-105697

    10000698
    58.1K followersView on X
  • AI Cyber Brief@justelite

    Langflow CVE-2026-105697 (CVSS 9.9): an MCP stdio server's command runs on the host on connect, even if the UI shows a failure. Default AUTO_LOGIN means exposed instances need no account. 1.9.0 isn't enough; fix is 1.10.3. MCP config is a shell. https://nvd.nist.gov/vuln/detail/CVE-2026-105697

    0000010
    1.7K followersView on X
  • Hephaestvs@Vulcanux_

    csirt_it: ‼️ #PoC #Langflow: disponibili Proof of Concept per le CVE-2026-105741, CVE-2026-105740, CVE-2026-105699 e CVE-2026-105697 Rischio: 🔴 Tra le tipologie: 🔸 Remote Code Execution 🔸 Security Feature Bypass 🔗 https://www.acn.gov.it/portale/w/langflow-disponibili-poc-per-lo-sfruttamento-di-4-vulnerabilita ⚠️ Impor… https://t.co/JvPD3v63dL

    0000011
    643 followersView on X

Explore more