CyberRota Analysis
AI-GeneratedAuthenticated users of Langflow versions prior to 1.9.0 are vulnerable to Remote Code Execution (RCE) due to insufficient validation of user-supplied commands, which are directly executed on the server. This critical flaw allows attackers to execute arbitrary commands and inject environment variables, potentially compromising the entire server. Organizations using Langflow should prioritize upgrading to version 1.9.0 to mitigate this severe risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with zero validation, no allowlisting, and no sandboxing. The command executes immediately when the server list is fetched. Additionally, the env field allows arbitrary environment variable injection (e.g., LD_PRELOAD, PATH override). This vulnerability is fixed in 1.9.0.