HighVulnerability
CVE-2026-105741: Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-105741
- Published
- Record updated
Summary
Langflow versions 1.5.0 through 1.10.3 contain an IP spoofing flaw in the MCP configuration installation endpoint, POST /api/v1/mcp/project/{project_id}/install. An authenticated remote attacker can send a spoofed X-Forwarded-For: 127.0.0.1 header, making the server treat the request as local and bypass the "local-only" restriction. This lets the attacker write or overwrite an MCP client configuration file on the server's filesystem.
Mitigation
Fixed in 1.10.3.
Topics
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database