Junglewise Threat Intelligence

CVE-2026-7755: IBM Langflow OSS remote code execution in MCP server configuration

CVE-2026-7755 · Severity: high · CVSS 8.8 · Published 2026-07-17

Technologies: IBM Langflow OSS. Vendors: IBM.

Executive brief

IBM Langflow OSS, a tool used for building multi-agent AI applications, is vulnerable to a security flaw that could allow an attacker to take control of the server. By uploading a specially crafted configuration file, an authenticated user can bypass security checks and execute unauthorized commands on the underlying system. This could lead to a complete compromise of the application, data theft, or disruption of services.

Technical details

A validation bypass exists in the Langflow File Manager API's upload_user_file() function. While the structured MCP API endpoint correctly validates server configurations, the file upload endpoint allows users to upload '_mcp_servers_<user_id>.json' files without invoking the MCPServerConfig validator. An authenticated attacker can upload a malicious JSON configuration containing dangerous environment variables or command arguments. When the application later enumerates these servers and calls MCPStdioClient._connect_to_server(), it spawns processes using the attacker-controlled parameters, leading to remote code execution. The issue is addressed in version 1.10.1.

Affected products

  • IBM Langflow OSS 1.0.0 through 1.10.0

Timeline

  • 2026-07-02: advisory: Initial publication by IBM
  • 2026-07-17: disclosed: NVD publication date
  • 2026-07-02: patched: Fix released in version 1.10.1

References