External risk intelligence

Langflow Arbitrary Command Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-105697

Langflow is a web-based application designed for building and deploying AI workflows. It exposes administrative and functional endpoints (such as API routes for managing MCP servers) via the network. While certain configurations are intended for development, the application is commonly deployed as a web service accessible to users or administrators over the network.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in Langflow, a tool used for building and deploying AI workflows. The issue allows an attacker with specific access to run arbitrary operating system commands on the host machine. This could potentially lead to significant compromise of the affected system.

  • Arbitrary command execution via server settings.
  • Confirms potential for unauthorized system control.
  • Assess exposure and confirm relevance to operations.

Attack Path

How an attacker could exploit the issue

An attacker could begin by configuring a malicious MCP server within Langflow's settings or by building a flow using the MCP Tools component. This allows them to specify arbitrary operating system commands that will execute on the host when Langflow attempts to connect to the server. This could lead to remote code execution on the Langflow host.

  • Exposed network access to server settings.
  • MCP server configuration with arbitrary commands.
  • Potential for arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an attacker could execute arbitrary operating system commands on the Langflow host by configuring an MCP server with malicious commands. This could occur when interacting with MCP server settings or building flows with the MCP Tools component, potentially without authentication on exposed instances with default settings.

  • Langflow host command execution.
  • Malicious commands in MCP server settings.
  • Unauthorized system access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and infrastructure teams are likely responsible for addressing this vulnerability in Langflow. The first practical step is to identify all instances of the affected technology, confirm their exposure and criticality, and then determine the accountable owner before planning remediation.

  • Application owners should manage this issue.
  • Verify network reachability and criticality first.
  • Plan remediation based on confirmed exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Langflow and how is it used?

Langflow is a visual development platform used to build and deploy AI-powered agents and workflows. It provides a web-based interface that allows users to connect various AI components, manage MCP (Model Context Protocol) servers, and automate data processing tasks. Developers and data scientists typically run it as a service to orchestrate complex language model interactions.

What does CWE-78 mean for CVE-2026-105697?

CWE-78, or OS Command Injection, occurs when an application passes unsanitized user input to a system shell. In the context of CVE-2026-105697, the vulnerability allows an attacker to inject arbitrary OS commands into the Langflow MCP server configuration. Because the system treats this input as a command to be executed, it enables the attacker to run unauthorized instructions directly on the host machine where Langflow is running.

How can an attacker trigger this command execution?

An attacker triggers the vulnerability by entering a malicious command into the MCP server settings or the MCP Tools component. The command executes as soon as Langflow attempts to connect to that server—even if the connection fails afterward. This does not happen if the user lacks access to the MCP server configuration menus or the ability to build flows containing the MCP Tools component.

Is my Langflow instance at risk?

According to Halo Surface Signal, Langflow instances are often deployed as web services accessible over the network. If your instance is reachable via the internet, or even internally if your default configuration enables auto-login, it may be accessible to unauthorized users. Because this vulnerability can lead to full system control, any instance where users have access to flow or server settings should be treated as a potential path for compromise.

How do I fix the Langflow vulnerability?

The primary response is to upgrade your environment. This issue is resolved in Langflow version 1.10.3, langflow-base version 0.10.3, and lfx version 1.10.3. Before updating, verify your current network exposure to prioritize the most accessible instances. Ensure that development-only settings like auto-login are disabled to prevent unauthenticated access while you coordinate the necessary version upgrades.

References