Langflow Patches CVSS 9.9 RCE in MCP Tool Handler
Any authenticated Langflow user on versions before 1.9.0 could execute arbitrary code on the server by adding a crafted MCP tool. Upgrade to 1.9.0 now.

Upgrade to Langflow 1.9.0. Any authenticated user on older versions could execute code on the server, no elevated permissions required.
Langflow, the open-source platform for building and deploying AI agent workflows, has patched a critical remote code execution vulnerability tracked as CVE-2026-105740. The CVSS score is 9.9. The patch is in version 1.9.0, released this week.
What the flaw is
Langflow exposes Model Context Protocol (MCP) as a first-class feature: users can add MCP servers and tools to connect AI workflows to external data sources and services. In versions before 1.9.0, the MCP tool handler did not enforce adequate server-side execution controls. An attacker with a valid Langflow account could add a crafted MCP tool and achieve remote code execution on the underlying server.
The CVSS 9.9 rating reflects one critical condition: the bar for exploitation is low. A standard account with no special roles is enough. In team deployments, that means any compromised credential becomes a direct path to the server.
What to do
Patch first. Three steps:
- Update to Langflow 1.9.0. The fix is in the official commit and available through the normal release channel.
- Audit account access. Langflow is often deployed as a shared team tool with broadly granted logins. Trim that list to people who actually need it.
- If you cannot patch immediately, disable or restrict MCP server and tool creation at the application level or via network controls until the update is applied.
Context: AI workflow tools keep generating severe RCE bugs
This is a recurring pattern. In September, researchers disclosed unauthenticated RCE in LightLLM’s config server and a critical root RCE in AutoAgent via unauthenticated TCP. Earlier in August, 13 CVEs across AshAdmin and AshAI included critical RCE paths.
The common thread: AI/ML tooling is built for development speed and flexibility, not for multi-tenant hardening. Features like MCP tool execution and pickle-based model loading are powerful by design and routinely turn into RCE surfaces when server-side controls are absent or incomplete. If your organization runs any AI workflow platform in a shared or internet-accessible environment, treat its patch cadence like any production web service.
- [ CRITICAL ]CVE-2026-105740Authenticated RCE via MCP tool addition
Found this useful? Share it.


