CVE-2026-105740

LOWCVSS 9.9 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with zero validation, no allowlisting, and no sandboxing. The command executes immediately when the server list is fetched. Additionally, the env field allows arbitrary environment variable injection (e.g., LD_PRELOAD, PATH override). This vulnerability is fixed in 1.9.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-10-06: 310-06
Referenced assets3 URLs
Full discourse3 posts
  • Hephaestvs@Vulcanux_

    csirt_it: ‼️ #PoC #Langflow: disponibili Proof of Concept per le CVE-2026-105741, CVE-2026-105740, CVE-2026-105699 e CVE-2026-105697 Rischio: 🔴 Tra le tipologie: 🔸 Remote Code Execution 🔸 Security Feature Bypass 🔗 https://www.acn.gov.it/portale/w/langflow-disponibili-poc-per-lo-sfruttamento-di-4-vulnerabilita ⚠️ Impor… https://t.co/JvPD3v63dL

    0000011
    643 followersView on X
  • CVE@CVEnew

    CVE-2026-105740 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RC… https://www.cve.org/CVERecord?id=CVE-2026-105740

    00000537
    58.1K followersView on X
  • The Hacker Wire@TheHackerWire

    🚨 CVE-2026-105740 (CVSS 9.9 Critical) Langflow allows authenticated attackers to execute arbitrary OS commands via unvalidated MCP Stdio server configurations. https://www.thehackerwire.com/vulnerability/CVE-2026-105740/ https://t.co/e4soCRC6Me

    0000034
    175 followersView on X

Explore more