Executive brief
IBM Langflow OSS, a tool used for building multi-agent AI applications, is vulnerable to a security flaw that could allow an attacker to take control of the server. By uploading a specially crafted configuration file, an authenticated user can bypass security checks and execute unauthorized commands on the underlying system. This could lead to a complete compromise of the application, data theft, or disruption of services.
Technical details
A validation bypass exists in the Langflow File Manager API's upload_user_file() function. While the structured MCP API endpoint correctly validates server configurations, the file upload endpoint allows users to upload '_mcp_servers_<user_id>.json' files without invoking the MCPServerConfig validator. An authenticated attacker can upload a malicious JSON configuration containing dangerous environment variables or command arguments. When the application later enumerates these servers and calls MCPStdioClient._connect_to_server(), it spawns processes using the attacker-controlled parameters, leading to remote code execution. The issue is addressed in version 1.10.1.
Affected products
- IBM Langflow OSS 1.0.0 through 1.10.0
Timeline
- 2026-07-02: advisory: Initial publication by IBM
- 2026-07-17: disclosed: NVD publication date
- 2026-07-02: patched: Fix released in version 1.10.1