HIGH

CVE-2026-17623

Langflow Langflow 2026-08-05 CVSS v3.1
CVSS
8.8

Description

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in MCP server configurations.

Summary dbcve.org

IBM Langflow OSS versions 1.0.0 through 1.10.3 contains a command injection vulnerability in MCP server configurations. An authenticated remote attacker can execute arbitrary OS commands on the host system due to insufficient validation of the command field in MCP server configurations.

Mitigation

Upgrade to IBM Langflow OSS version 1.10.4 or later which contains the fix for this vulnerability. If upgrading is not immediately possible, implement strict allow-list validation on the command field in MCP server configurations to prevent command injection attacks.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

0.96%
Probability of exploitation in next 30 days
60.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE