Langflow MCP Stdio Config Allowed Arbitrary OS Commands, Enabling RCE (Fixed in 1.10.3)
What happened
A GitHub Security Advisory (GHSA-w794-rj3p-xv45, CVE-2026-105697) details an OS command injection flaw in Langflow's MCP stdio transport. Before Langflow 1.10.3, any user who could reach MCP server settings (Settings → MCP Servers → Add MCP Server, or the POST/PATCH /api/v2/mcp/servers/{server_name} API) or build a flow using the MCP Tools component could supply an arbitrary command/args pair. Versions from 1.5.0 through 1.10.2 launched that command via bash -c "exec {command} ..." with no validation at the execution sink, even after an allowlist was added to the REST API in 1.9.0 — configs embedded in flows or tweaks bypassed it. The command runs on the Langflow host as the Langflow process user as soon as Langflow attempts to connect, regardless of whether the UI later reports a connection failure.
With the default LANGFLOW_AUTO_LOGIN=true (documented as development-only), an unauthenticated caller can obtain a token from /api/v1/auto_login and exploit this directly. With auto-login disabled, any authenticated non-admin user can still trigger it. The reporter states several internet-facing Langflow servers were found vulnerable.
Why it matters for defenders
This is remote code execution (CWE-78) rated CVSS 9.9 with a public PoC, affecting the langflow, langflow-base, and lfx PyPI packages (vulnerable ranges roughly ≥1.1.2 <1.10.3, ≥0.1.2 <0.10.3, and <1.10.3 respectively). Any organization running a self-hosted Langflow instance — particularly one exposed to the internet or to untrusted internal users, or left on the default auto-login setting — should treat this as a direct path to host compromise. The fix is fully effective only at 1.10.3+, where the command policy is enforced consistently at the API, flow-execution, and pre-spawn boundaries and the shell wrapper is removed.
What defenders should watch for or do now
- Inventory Langflow deployments and check version against the vulnerable ranges above; prioritize upgrading to 1.10.3 or 1.11.0+.
- If upgrading isn't immediate, set
LANGFLOW_AUTO_LOGIN=falseand ensure Langflow is not reachable from untrusted networks; restrict accounts to trusted users only. - Hunt for unexpected child processes spawned by the Langflow process (e.g.,
bash,sh, reverse-shell patterns, or unexpected binaries liketouch/rm) originating from the Langflow service user. - Review audit logs or database records for MCP server configurations with unexpected
commandvalues, and review flows/tweaks for embedded MCP Tools component configs that bypass the settings UI. - On 1.10.3+, note the allowlist still permits
npx/uvxto run arbitrary packages by default — multi-tenant operators should additionally configureLANGFLOW_MCP_SERVER_ALLOWED_PACKAGES, interpreter/Docker hardening flags, and (on 1.11.1+) custom-component restrictions.
Developing intel
This advisory was published 2026-10-07 and details are still being digested by the community; treat specifics around exploitation in the wild (beyond the reporter's internet-facing scan) as unconfirmed. For full technical detail, affected-version tables, and remediation guidance, see the original GitHub Security Advisory: GHSA-w794-rj3p-xv45.