External risk intelligence

Langflow Unauthenticated Remote Code Execution via MCP Stdio Transport

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-105740

Langflow is a web-based platform designed for building and deploying AI agents and workflows. As a development and deployment tool, it is commonly hosted as a web application or API service accessible to users and developers, making internet-facing or reachable-internal-network deployment a standard pattern for its operation.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Langflow, a tool used for building and deploying AI agents and workflows. The issue allows any authenticated user to execute arbitrary commands on the server, potentially leading to a complete system compromise. This is due to a lack of validation when processing user-supplied commands.

  • Unvalidated user commands allow server code execution.
  • Critical flaw affects AI agent building and deployment.
  • Focus on confirming relevance and exposure.

Attack Path

How an attacker could exploit the issue

An authenticated user in Langflow can execute arbitrary commands on the server by adding a new MCP server with specific configurations. This is possible because the command field is directly passed to a bash shell without any checks or restrictions. The vulnerability can be triggered when the server list is accessed, allowing for remote code execution and environment variable manipulation.

  • Authenticated user access required.
  • Adding MCP server with \"Stdio\" transport.
  • Remote code execution and environment variable control.

Live Threat

Current exploitation, exposure, and threat context

An authenticated user of Langflow could potentially execute arbitrary commands on the server when adding an MCP server with a \"Stdio\" transport. This could occur due to insufficient validation of user-supplied commands, allowing for direct execution through bash, and enabling environment variable injection.

  • Server-side code execution.
  • Malicious commands submitted by an authenticated user.
  • Complete server compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

To address this critical vulnerability, the platform or application owners responsible for Langflow deployments are the primary point of contact. The immediate first step is to inventory all Langflow instances, confirm their reachability and business criticality, identify the specific team or individual accountable for each instance, and then prioritize remediation efforts based on risk assessment.

  • Platform owners must own this issue.
  • Verify Langflow instance reachability and criticality.
  • Plan remediation based on identified risks.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Langflow and how is it used?

Langflow is a visual development platform designed for building, testing, and deploying AI-powered agents and complex workflows. It provides a web-based interface that allows developers and data scientists to assemble AI applications by connecting components. Because it acts as an orchestration hub for AI services, it is typically hosted as a central server or API service accessible to development teams.

How does CVE-2026-105740 enable remote code execution?

This vulnerability, classified as CWE-78 (OS Command Injection), occurs because the software fails to sanitize input when handling MCP server configurations. By using the 'Stdio' transport, an attacker can pass malicious input directly to a bash shell. This allows the system to execute unauthorized commands or manipulate environment variables, effectively giving the attacker control over the underlying server operating system.

Do I need to trigger this bug to be at risk?

Yes, this vulnerability requires an authenticated user to perform specific actions. An attacker must successfully add an MCP server configuration using the 'Stdio' transport. The malicious command is triggered automatically when the server list is fetched by the application. Simply having an account is not enough; the attacker must intentionally submit the malformed configuration to initiate the execution.

Why should I care about this Langflow CVE?

Halo Surface Signal indicates that Langflow is frequently deployed as a web application or API service, often making it reachable via internal networks or directly from the internet. Because this flaw allows for complete server compromise, any instance accessible to users—even those you might consider internal—represents a high-risk entry point if an account is compromised.

How do I address this security issue?

The primary resolution is to update your Langflow deployment to version 1.9.0 or later, which includes the necessary input validation to prevent command injection. Before updating, inventory all active Langflow instances across your environment to assess which are currently reachable. Coordinate with the teams responsible for these instances to ensure the update is applied as the immediate priority.

References