IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7279995 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-07-30 17:16
Updated : 2026-08-04 20:20
NVD link : CVE-2026-12940
Mitre link : CVE-2026-12940
CVE.ORG link : CVE-2026-12940
JSON object : View
Products Affected
langflow
- langflow
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
