ZeroHour

CVE-2026-81941

large

Authenticated OS Command Execution in IBM Langflow OSS via MCP Tools stdio Transport

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM Langflow OSS versions 1.0.0 through 1.11.5 contain an improper access control flaw (CWE-284) that lets an authenticated non-administrative user execute arbitrary operating system commands on the server at the privilege level of the application process. It is triggered by constructing a flow that includes an MCP Tools component configured to use a local stdio subprocess transport, which spawns the subprocess without honoring server-side restrictions. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS controls that are specifically intended to prevent this class of access. A successful attacker gains arbitrary command execution, access to sensitive data including credentials from the process environment, the ability to modify the file system, and a path for lateral movement to services reachable from the server; CVSS rates this 8.8 (high). Any deployment running affected versions in which non-admin users can build flows is affected; there is currently no known exploitation, no public proof-of-concept, and the issue is not in CISA's KEV.

What to do: Upgrade Langflow to a release later than 1.11.5 as directed by IBM's advisory (no fixed version number is stated in this data), prioritizing instances where non-admin users can create or edit flows. Until patched, restrict flow creation and editing to trusted administrators, avoid exposing the Langflow server to untrusted networks, and limit secrets in the application process environment plus its lateral network reach. Note that the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS controls do not mitigate this issue, since both are bypassed.

Affected
IBM Langflow OSS1.0.0 through 1.11.5
Estimated exposure
large≈100,000+ users across tens of thousands of self-hosted and managed deployments (estimate) — The affected range spans the entire current 1.x release line of Langflow, one of the most widely adopted open-source AI agent/workflow builders, so the vulnerable installed base plausibly covers a large share of its community of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS server-side controls intended to prevent exactly this class of access. Successful exploitation could lead to arbitrary command execution, sensitive data exposure (including credentials from the process environment), file system modification, and lateral movement to services reachable from the server.

Vendors
langflow
Products
langflow
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.