Vulnerabilities · 11h ago

Langflow PoCs Expose Header Trust and MCP RCE

CSIRT Italia and ACN say proof-of-concept code is now available for four Langflow vulnerabilities, including two critical OS command injection flaws and two high-severity access-control bugs. The affected releases are Langflow 1.1.2 through 1.10.2, langflow-base 0.1.2 through 0.10.2, and lfx versions before 1.10.3.

One flaw lets a remote request spoof X-Forwarded-For and look local, which can open routes meant only for localhost and allow writes to MCP configuration files. The MCP issues go further: one can pass command values into bash for arbitrary command execution, and another can reveal flow IDs and file names so an authenticated user can reach other projects' or tenants' files.

For teams using Langflow as an internal AI workflow platform, the trust boundary is now the point of failure: a reverse proxy or 'local-only' gate is not enough if the app trusts header data. The reporting does not say exploitation is underway, but public PoCs lower the barrier for anyone who can reach the service.

CVE-2026-105697

NVD KEV

CVSS 9.9 CRITICAL: langflow is a tool for building and deploying AI-powered agents and workflows.

CVE-2026-105740

NVD KEV

CVSS 9.9 CRITICAL: langflow is a tool for building and deploying AI-powered agents and workflows.

CVE-2026-105741

NVD KEV

CVSS 7.1 HIGH: langflow is a tool for building and deploying AI-powered agents and workflows.

CVE-2026-105699

NVD KEV

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-10-06

Editions

Related stories