Langflow 是一款用于构建和部署 AI 驱动的智能体(agents)与工作流的工具。在 Langflow 1.10.3 版本之前,MCP 的 stdio 传输机制会执行用户在任何 MCP 服务器配置中提供的任意命令/参数,且未设置任何白名单限制。此外,在 1.10.3 之前,这些命令还被包裹在 中执行。 任何能够访问 MCP 服务器设置界面(路径为:“Settings → MCP Servers → Add MCP Server”,或通过 HTTP POST/PATCH 请求 )的用户,或者能够使用 MCP
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| langflow-ai | langflow | >= 1.1.2, < 1.10.3 | - |
|
| langflow-ai | langflow-base | >= 0.1.2, < 0.10.3 | - |
|
| langflow-ai | lfx | < 1.10.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105740 | 9.9 CRITICAL | Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary O |
| CVE-2026-105699 | 7.1 HIGH | Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers |
| CVE-2026-105741 | 7.1 HIGH | Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write |
| CVE-2026-105698 | 5.4 MEDIUM | Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_i |
No comments yet