Junglewise Threat Intelligence

CVE-2026-17623: IBM Langflow OS command injection in MCP server configurations

CVE-2026-17623 · Severity: high · CVSS 8.8 · Published 2026-08-05

Technologies: IBM Langflow OSS, Langflow. Vendors: IBM, Langflow.

Executive brief

IBM Langflow is an open-source platform for building AI workflows that supports external server connections through Model Context Protocol (MCP). A vulnerability in versions 1.0.0 through 1.10.3 allows authenticated attackers to execute arbitrary commands on the Langflow server by injecting malicious input into MCP server configuration fields. An attacker with valid credentials could gain complete control over the server, leading to data theft, system compromise, and potential lateral movement to other infrastructure.

Technical details

CVE-2026-17623 is an OS command injection vulnerability (CWE-78) in IBM Langflow OSS 1.0.0–1.10.3 caused by improper validation of the command field in MCP server configurations. The vulnerability requires prior authentication (PR:L) but has network accessibility (AV:N) and no user interaction (UI:N). An authenticated attacker can inject special shell metacharacters and OS commands into the configuration field to achieve arbitrary command execution in the Langflow server process context. This allows complete system compromise including reading files, modifying data, and executing arbitrary code. Remediation is available via upgrade to Langflow OSS 1.11.0 or later.

Affected products

  • IBM Langflow OSS 1.0.0 through 1.10.3

Timeline

  • 2026-08-05: disclosed
  • 2026-08-05: patched: Fix available in Langflow OSS 1.11.0

References

Related threats