Skip to content
feed: live
0dayNews
ai tools

Langflow Patches CVSS 9.9 RCE in MCP Tool Handler

Any authenticated Langflow user on versions before 1.9.0 could execute arbitrary code on the server by adding a crafted MCP tool. Upgrade to 1.9.0 now.

Langflow Patches CVSS 9.9 RCE in MCP Tool Handler
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·1 min read

Upgrade to Langflow 1.9.0. Any authenticated user on older versions could execute code on the server, no elevated permissions required.

Langflow, the open-source platform for building and deploying AI agent workflows, has patched a critical remote code execution vulnerability tracked as CVE-2026-105740. The CVSS score is 9.9. The patch is in version 1.9.0, released this week.

What the flaw is

Langflow exposes Model Context Protocol (MCP) as a first-class feature: users can add MCP servers and tools to connect AI workflows to external data sources and services. In versions before 1.9.0, the MCP tool handler did not enforce adequate server-side execution controls. An attacker with a valid Langflow account could add a crafted MCP tool and achieve remote code execution on the underlying server.

The CVSS 9.9 rating reflects one critical condition: the bar for exploitation is low. A standard account with no special roles is enough. In team deployments, that means any compromised credential becomes a direct path to the server.

What to do

Patch first. Three steps:

  1. Update to Langflow 1.9.0. The fix is in the official commit and available through the normal release channel.
  2. Audit account access. Langflow is often deployed as a shared team tool with broadly granted logins. Trim that list to people who actually need it.
  3. If you cannot patch immediately, disable or restrict MCP server and tool creation at the application level or via network controls until the update is applied.

Context: AI workflow tools keep generating severe RCE bugs

This is a recurring pattern. In September, researchers disclosed unauthenticated RCE in LightLLM’s config server and a critical root RCE in AutoAgent via unauthenticated TCP. Earlier in August, 13 CVEs across AshAdmin and AshAI included critical RCE paths.

The common thread: AI/ML tooling is built for development speed and flexibility, not for multi-tenant hardening. Features like MCP tool execution and pickle-based model loading are powerful by design and routinely turn into RCE surfaces when server-side controls are absent or incomplete. If your organization runs any AI workflow platform in a shared or internet-accessible environment, treat its patch cadence like any production web service.

Related CVEs

Found this useful? Share it.