CSIRT Italia and ACN say proof-of-concept code is now available for four Langflow vulnerabilities, including two critical OS command injection flaws and two high-severity access-control bugs. The affected releases are Langflow 1.1.2 through 1.10.2, langflow-base 0.1.2 through 0.10.2, and lfx versions before 1.10.3.
One flaw lets a remote request spoof X-Forwarded-For and look local, which can open routes meant only for localhost and allow writes to MCP configuration files. The MCP issues go further: one can pass command values into bash for arbitrary command execution, and another can reveal flow IDs and file names so an authenticated user can reach other projects' or tenants' files.
For teams using Langflow as an internal AI workflow platform, the trust boundary is now the point of failure: a reverse proxy or 'local-only' gate is not enough if the app trusts header data. The reporting does not say exploitation is underway, but public PoCs lower the barrier for anyone who can reach the service.
Disponibili Proof of Concept (PoC) per lo sfruttamento di 4 nuove vulnerabilità di sicurezza, di cui 2 con gravità “critica” e 2 con gravità “alta”, che interessano il software Langflow, nota piattaforma open-source che permette di costruire, testare e distribuire applicazioni e agenti basati su intelligenza artificiale.