Answer in brief
CVE-2026-105697 records a Critical severity (CVSS 9.9) vulnerability in Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration. The current sources do not mark it as known exploited. The current feed maps langflow-ai/langflow (generic), langflow-ai/langflow-base (generic), langflow-ai/lfx (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.9. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps langflow-ai/langflow (generic), langflow-ai/langflow-base (generic), langflow-ai/lfx (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| langflow-ai/langflowgeneric | >=1.1.2 <1.10.3 | 1.10.3 |
| langflow-ai/langflow-basegeneric | >=0.1.2 <0.10.3 | 0.10.3 |
| langflow-ai/lfxgeneric | <1.10.3 | 1.10.3 |
Published upstream
Oct 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 5, 2026
Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in bash -c "exec {command} ...". Any user able to reach the MCP server settings ("Settings → MCP Servers → Add MCP Server", POST/PATCH /api/v2/mcp/servers/{server_name}) or to build a flow with the MCP Tools component could add a "server" whose command is an arbitrary OS command (touch, rm -rf, a reverse shell, ...). The command runs on the Langflow host as the Langflow process user as soon as Langflow tries to connect to the server (listing servers, loading tools, running the flow) — even when the UI then reports that the stdio server failed to start. With the default LANGFLOW_AUTO_LOGIN=true, GET /api/v1/auto_login hands out a token without credentials, so on an exposed instance running the default configuration this is reachable without an account. AUTO_LOGIN is documented as a development-only setting; with it disabled, any authenticated (non-admin) user can exploit it. This issue is fixed in Langflow 1.10.3, langflow-base 0.10.3, and lfx 1.10.3.
Quoted source text, attributed separately from HOL analysis.