Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration
Summary
Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in bash -c "exec {command} ...". Any user able to reach the MCP server settings ("Settings → MCP Servers → Add MCP Server", POST/PATCH /api/v2/mcp/servers/{server_name}) or to build a flow with the MCP Tools component could add a "server" whose command is an arbitrary OS command (touch, rm -rf, a reverse shell, ...). The command runs on the Langflow host as the Langflow process user as soon as Langflow tries to connect to the server (listing servers, loading tools, running the flow) , even when the UI then reports that the stdio server failed to start.
With the default LANGFLOW_AUTO_LOGIN=true, GET /api/v1/auto_login hands out a token without credentials, so on an exposed instance running the default configuration this is reachable without an account. AUTO_LOGIN is documented as a development-only setting; with it disabled, any authenticated (non-admin) user can exploit it.
The issue was fixed in two steps and is fully fixed in Langflow 1.10.3 (and 1.11.0+):
- 1.9.0 , #12290 added a command allowlist and argument/env validation to the REST model (
MCPServerConfig), blocking the "Add MCP Server" vector reported here. - 1.10.3 , #14036 applied the same policy...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| langflow PyPI | >= 1.1.2, < 1.10.3 | 1.10.3 |
Details and references
### Summary Before **Langflow 1.10.3**, the MCP stdio transport launched whatever `command` / `args` a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in `bash -c "exec {command} ..."`. Any user able to reach the MCP server settings ("Settings → MCP Servers → Add MCP Server", `POST/PATCH /api/v2/mcp/servers/{server_name}`) or to build a flow with the MCP Tools component could add a "server" whose command is an arbitrary OS command (`touch`, `rm -rf`, a reverse shell, ...). The command runs on the Langflow host as the Langflow process user as soon as Langflow tries to connect to the server (listing servers, loading tools, running the flow) , even when the UI then reports that the stdio server failed to start. With the default `LANGFLOW_AUTO_LOGIN=true`, `GET /api/v1/auto_login` hands out a token without credentials, so on an exposed instance running the default configuration this is reachable without an account. `AUTO_LOGIN` is documented as a development-only setting; with it disabled, any authenticated (non-admin) user can exploit it. The issue was fixed in two steps and is **fully fixed in Langflow 1.10.3** (and 1.11.0+): - **1.9.0** , #12290 added a command allowlist and argument/env validation to the REST model (`MCPServerConfig`), blocking the "Add MCP Server" vector reported here. - **1.10.3** , #14036 applied the same policy at the execution sink (`lfx.base.mcp.util`), including configs embedded in flows / tweaks and the final pre-spawn boundary, and removed the `bash -c` wrapper (the process is now exec'd directly, without a shell). ### Affected versions | Package (PyPI) | Vulnerable | Patched | |---|---|---| | `langflow` | `>= 1.1.2, < 1.10.3` | `1.10.3` | | `langflow-base` | `>= 0.1.2, < 0.10.3` | `0.10.3` | | `lfx` | `< 1.10.3` | `1.10.3` | | Release | State | |---|---| | `1.1.2` – `1.4.x` | MCP Stdio component (added in #5148) runs `StdioServerParameters(command=..., args=...)` from the component's `command` field with no validation. | | `1.5.0` – `1.8.x` | "Add MCP Server" settings page and `/api/v2/mcp/servers` API added (#8388). Stored stdio configs are launched via `bash -c "exec {command_str} ..."` with no validation. The PoC below works as-is. | | `1.9.0` – `1.10.2` | #12290: `POST`/`PATCH /api/v2/mcp/servers` reject commands outside the allowlist. The execution sink still has no validation and still uses `bash -c`, so configs that do not go through `MCPServerConfig` (for example an MCP Tools component value embedded in a flow or passed as a tweak) can still execute arbitrary commands. | | `1.10.3`+ | #14036: one shared policy (`lfx.base.mcp.security.validate_mcp_stdio_config`) is enforced at the API, at flow execution and right before the process is spawned; no shell is used. **Fixed.** | ### Details Vulnerable sink (`src/lfx/src/lfx/base/mcp/util.py`, `MCPStdioClient._connect_to_server`, before 1.10.3): ```python server_params = StdioServerParameters( command="bash", args=["-c", f"exec {command_str} || echo 'Command failed with exit code $?' >&2"], env=env_data, ) ``` `command_str` is built from the user's `command` + `args`. The only "validation" before 1.9.0 was `_validate_node_installation`, which only checks that Node.js is installed when the command contains `npx`. The MCP SDK then starts the process with `anyio.open_process`, so the command runs before any MCP handshake , which is why it executes even if the UI shows "failed to start". ### PoC (as reported, Langflow 1.5.0 – 1.8.x) In "Add MCP Server" → STDIO, add: ``` Name - Test Command - touch Arguments - /tmp/pwn ``` Or through the API, using a token from `auto_login` (default configuration): ```bash TOKEN=$(curl -s http://127.0.0.1:7860/api/v1/auto_login | python3 -c 'import sys,json;print(json.load(sys.stdin)["access_token"])') curl -s -X POST 'http://127.0.0.1:7860/api/v2/mcp/servers/testing' \ -H "Authorization: Bearer $TOKEN" \ -H 'Content-Type: application/json
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-78
- Also known as
- CVE-2026-105697
- github.com/langflow-ai/langflow/security/advisories/GHSA-w794-rj3p-xv45
- nvd.nist.gov/vuln/detail/CVE-2026-105697
- github.com/langflow-ai/langflow/pull/12290
- github.com/langflow-ai/langflow/pull/14036
- github.com/langflow-ai/langflow/commit/eba285edf1dd4a33bf23a9cb8113c991fcdf3d1d
- github.com/langflow-ai/langflow/commit/efbc4a16e639409d938a4883463d27ef0bc637a0
- github.com/langflow-ai/langflow
- github.com/langflow-ai/langflow/releases/tag/v1.10.3
More Langflow advisories
All Langflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 7 | Langflow: insecure direct object reference | Medium5.4 | 1.10.1 |
| Oct 7 | Langflow has Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers | High | 1.9.1 |
| Oct 7 | Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write | High7.1 | 1.10.3 |
| Oct 6 | Langflow: server-side request forgery | Medium | 1.10.3 |
| Oct 6 | Langflow: remote code execution | Critical9.9 | 1.10.1 |
| Oct 5 | Langflow: Weak Fernet Key via random.seed() | Critical9.1 | 1.10.1 |