CVE-2026-12940(langflow / langflow)

LOWCVSS 9.8 · CRITICAL

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Affected systems

Vendors
Products
langflow

Deep dive

Full discourse5 posts
  • ThreatWire@ThreatWire_
    PoC

    🚨 A public PoC has been released for CVE-2026-12940 affecting IBM Langflow OSS. The vulnerability allows unauthenticated RCE via environment variable injection in the MCP stdio launcher. 🔗 https://github.com/biitts/cve-2026-12940-langflow-unauth-rce #Langflow #RCE #CVE #CyberSecurity

    Post summary

    A public proof of concept for CVE-2026-12940 has been released, detailing an unauthenticated RCE via environment variable injection in IBM Langflow OSS, but no active exploitation or patch information is provided.

    013030151.9K
    1.0K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-12940 PT ID: PT-2026-66519 Vendor: IBM Product: Langflow OSS Description: IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-66519 • https://github.com/biitts/cve-2026-12940-langflow-unauth-rce #dbugs_vuln

    Post summary

    A Proof of Concept for CVE-2026-12940 has been discovered and shared, demonstrating unauthenticated remote code execution via environment variable injection in IBM Langflow OSS. No active exploitation or patch information is provided.

    00033735
    3.4K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-12940 (CVSS 9.8) IBM Langflow OSS 1.0.0-1.10.1 vulnerable to unauthenticated RCE via environment variable injection in MCP stdio launcher. No authentication required. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/yCgMrVdr28

    Post summary

    Critical unauthenticated RCE disclosed for IBM Langflow OSS; a patch is urgently recommended to address the high‑severity vulnerability.

    0001049
    99 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-12940: IBM Langflow OSS Unauthenticated Remote Code Execution via Environment Variable Injection - What It Means for Your Business and How to Respond https://hubs.li/Q04wZLVh0

    Post summary

    The text highlights the nature of CVE-2026-12940 and suggests business impact and response strategies, but lacks details on exploits, patches, or active use.

    0000035
    35 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #PoC #IBM: disponibile Proof of Concept (PoC) per la CVE-2026-12940 in #LangFlow #OSS Rischio: 🟠 Tipologia: 🔸 Remote Code Execution 🔗 https://www.acn.gov.it/portale/w/langflow-poc-pubblico-per-lo-sfruttamento-della-cve-2026-12940 ⚠️ Importante mantenere aggiornati i sistemi https://t.co/1rZzhsiWJq

    Post summary

    The post announces a publicly available Proof of Concept for CVE-2026-12940, highlighting its Remote Code Execution nature and advising users to keep systems updated.

    0000052
    628 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more