CVE-2026-105741High· 7.1▾ TwilightLangflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{proje…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the "local-only" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an attacker could make the server treat the request as originating from localhost, letting them write/overwrite an MCP client configuration file on the server's filesystem. This vulnerability is fixed in 1.10.3.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-7700High· 8.8Langflow: Prompt injection in Langflow Smart Transform can lead to code execution
CVE-2026-105697Critical· 9.9Langflow is a tool for building and deploying AI-powered agents and workflows
CVE-2026-105698Medium· 5.4Langflow is a tool for building and deploying AI-powered agents and workflows
CVE-2026-105699High· 7.1Langflow is a tool for building and deploying AI-powered agents and workflows
CVE-2026-105740Critical· 9.9Langflow is a tool for building and deploying AI-powered agents and workflows
CVE-2026-51886High· 8.8langflow-ai langflow v1.9.3 is affected by: Code Injection