PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105741 langflow-ai CVE debrief

An IP spoofing vulnerability in Langflow's Model Context Protocol (MCP) configuration installation endpoint allowed authenticated remote attackers to bypass the 'local-only' access restriction by sending a spoofed `X-Forwarded-For: 127.0.0.1` header. This enables them to write/overwrite an MCP client configuration file on the server's filesystem. The vulnerability was introduced by commit `d3d06be8e5` in version 1.5.0 and was fixed in version 1.10.3. Langflow users and administrators should assess exposure and prioritize verification and remediation efforts to prevent authenticated remote attackers from bypassing access restrictions to write configuration files.

Vendor
langflow-ai
Product
langflow
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Langflow users and administrators should assess exposure and prioritize verification and remediation efforts to prevent authenticated remote attackers from bypassing access restrictions to write configuration files.

Why it matters

Authenticated remote attackers could bypass access restrictions to write configuration files in Langflow. Assess exposure and prioritize verification and remediation efforts.

  • Authenticated remote attackers could bypass access restrictions to write configuration files
  • Successful exploitation could lead to configuration file tampering
  • Verification of patch application is necessary to prevent exploitation
  • Remediation priority is high due to potential for configuration file compromise

Technical summary

The `get_client_ip` helper function in Langflow's MCP configuration installation endpoint trusted the leftmost entry of `X-Forwarded-For` without checking for a trusted proxy. This allowed authenticated remote attackers to bypass the 'local-only' access restriction. The vulnerability lived in the `get_client_ip` helper, used to enforce the local-only gate for `install_mcp_config`. It trusted the leftmost (fully client-controlled) entry of `X-Forwarded-For` unconditionally, with no check for whether the request had actually passed through a trusted proxy.

Defensive priority

Authenticated remote attackers could bypass access restrictions to write configuration files. Assess exposure and prioritize verification and remediation efforts.

Recommended defensive actions

  • Verify and apply the patch in version 1.10.3 or later
  • Restrict access to the MCP configuration installation endpoint
  • Monitor for suspicious activity on the server's filesystem
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability was introduced by commit `d3d06be8e5` in version 1.5.0 and was fixed in version 1.10.3. The `get_client_ip` helper function trusted the leftmost entry of `X-Forwarded-For` without checking for a trusted proxy.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105741 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105741

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105741 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105741

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-4f6c-2vvp-gw82.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/langflow-ai/langflow/security/advisories/GHSA-4f6c-2vvp-gw82

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/langflow-ai/langflow/pull/13915

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/langflow-ai/langflow/commit/1f39a4b9d62c9dfa1b21fa7f85e23a180c351b72

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/langflow-ai/langflow/commit/94859df33acd70b2a1f816e26d68f5e89a7e5639

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/langflow-ai/langflow

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/langflow-ai/langflow/releases/tag/v1.10.3

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.