Skip to content
feed: live
0dayNews
CVE Record
[ CRITICAL ]CVE-2026-105740

Authenticated RCE via MCP tool addition

Any authenticated Langflow user before version 1.9.0 can execute arbitrary code on the server by adding a crafted MCP server or tool. Patch to 1.9.0 immediately.

Vendor
Langflow
Product
Langflow (prior to 1.9.0)
CVSS
9.9
EPSS (exploit probability)
0.6%
Status
patched
Published

CVE-2026-105740 affects Langflow, the open-source platform for building and deploying AI agent workflows. In versions prior to 1.9.0, the Model Context Protocol (MCP) server and tool handler did not adequately restrict execution on the server side. Any authenticated user could add a malicious MCP tool and trigger remote code execution on the server without needing elevated permissions.

The CVSS score of 9.9 reflects the low attack complexity and low privileges required: a standard account is enough. The flaw is patched in version 1.9.0.

What to do: Update to Langflow 1.9.0 or later. Audit account access on shared or multi-user instances. If patching is delayed, restrict MCP tool creation at the application or network level.