{"data":{"id":"4b29cc58-37e5-47d3-9fc9-f5326011ee11","title":"CVE-2026-105697: Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio tra","summary":"Langflow, a tool for building AI-powered agents and workflows, has a critical vulnerability where users can execute arbitrary operating system commands by adding malicious MCP servers (server configurations that connect to external tools). An attacker can reach this feature through the settings panel or by building a flow with MCP Tools, and the malicious command runs immediately when Langflow tries to connect to the server, with the highest privileges if auto-login is enabled.","solution":"Update to Langflow 1.10.3, langflow-base 0.10.3, or lfx 1.10.3. Additionally, disable the LANGFLOW_AUTO_LOGIN setting, which is documented as development-only, to prevent unauthenticated access on exposed instances.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105697","publishedAt":"2026-10-05T21:16:35.087Z","cveId":"CVE-2026-105697","cweIds":["CWE-78"],"cvssScore":"9.9","cvssSeverity":"critical","severity":"critical","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["Langflow"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-10-05T21:16:35.087Z","capecIds":["CAPEC-88"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0010"]}}