Authenticated RCE via MCP tool addition
Any authenticated Langflow user before version 1.9.0 can execute arbitrary code on the server by adding a crafted MCP server or tool. Patch to 1.9.0 immediately.
- Vendor
- Langflow
- Product
- Langflow (prior to 1.9.0)
- CVSS
- 9.9
- EPSS (exploit probability)
- 0.6%
- Status
- patched
- Published
CVE-2026-105740 affects Langflow, the open-source platform for building and deploying AI agent workflows. In versions prior to 1.9.0, the Model Context Protocol (MCP) server and tool handler did not adequately restrict execution on the server side. Any authenticated user could add a malicious MCP tool and trigger remote code execution on the server without needing elevated permissions.
The CVSS score of 9.9 reflects the low attack complexity and low privileges required: a standard account is enough. The flaw is patched in version 1.9.0.
What to do: Update to Langflow 1.9.0 or later. Audit account access on shared or multi-user instances. If patching is delayed, restrict MCP tool creation at the application or network level.
