Junglewise Threat Intelligence

CVE-2026-81941: IBM Langflow OSS privilege escalation in MCP Tools component

CVE-2026-81941 · Severity: high · CVSS 8.8 · Published 2026-09-10

Technologies: IBM Langflow OSS, Langflow. Vendors: IBM, Langflow.

Executive brief

IBM Langflow is a low-code platform for building AI assistant workflows. An authenticated user without administrative privileges can bypass security controls and execute arbitrary operating system commands by creating a workflow that uses the MCP Tools component with local subprocess transport. Exploitation can lead to unauthorized command execution, credential theft, file modification, and lateral movement within the network.

Technical details

This vulnerability is an authorization bypass (CWE-284) in IBM Langflow OSS versions 1.0.0 through 1.11.5. The MCP Tools component circumvents server-side execution controls (LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS) when invoked through a flow, allowing authenticated non-admin users to execute arbitrary OS commands at the privilege level of the application process. The attack requires authentication but no special user interaction. Successful exploitation grants full command execution capability, enabling sensitive data exposure from process environment, file system modification, and lateral movement to networked services. A patch is required to enforce execution policy checks on the MCP Tools component.

Affected products

  • IBM Langflow OSS 1.0.0 through 1.11.5

Timeline

  • 2026-09-10: disclosed

References

Related threats