CVE-2026-105697P2CRITICALCVSS 9.9fixed in 1.10.32026-10-05
CVE-2026-105697 [CRITICAL] CWE-78 CVE-2026-105697: Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.
Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in bash -c "exec {command} ...". Any user able to reach the MCP server settings ("Settings → MCP Se
nvd