Langflow 是一款用于构建和部署 AI 驱动代理和工作流的工具。在 1.9.0 版本之前,任何经过身份验证的 Langflow 用户都可以通过添加使用“Stdio”传输方式的 MCP 服务器,在服务器上实现远程代码执行(RCE)。用户提供的命令字段会直接传递给 ,没有任何验证、白名单限制或沙箱保护。当获取服务器列表时,该命令会立即执行。此外, 字段允许任意环境变量注入(例如 LD_PRELOAD、PATH 覆盖等)。该漏洞已在 1.9.0 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| langflow-ai | langflow | < 1.9.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105697 | 9.9 CRITICAL | Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configurati |
| CVE-2026-105699 | 7.1 HIGH | Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers |
| CVE-2026-105741 | 7.1 HIGH | Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write |
| CVE-2026-105698 | 5.4 MEDIUM | Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_i |
No comments yet