Langflow 是一款用于构建和部署 AI 驱动的智能体和工作流的工具。在版本 1.5.0 至 1.10.3 中,模型上下文协议(Model Context Protocol, MCP)配置安装端点(POST /api/v1/mcp/project/{project_id}/install)存在 IP 地址欺骗漏洞。该漏洞允许经过身份验证的远程攻击者绕过“仅限本地访问”的安全限制。攻击者通过发送伪造的 请求头,可以使服务器将该请求视为来自本地主机(localhost),从而在服务器文件系统上写入或覆盖 MCP 客
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| langflow-ai | langflow | >= 1.5.0, < 1.10.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105697 | 9.9 CRITICAL | Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configurati |
| CVE-2026-105740 | 9.9 CRITICAL | Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary O |
| CVE-2026-105699 | 7.1 HIGH | Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers |
| CVE-2026-105698 | 5.4 MEDIUM | Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_i |
No comments yet