PatchSiren cyber security CVE debrief
CVE-2026-105741 langflow-ai CVE debrief
An IP spoofing vulnerability in Langflow's Model Context Protocol (MCP) configuration installation endpoint allowed authenticated remote attackers to bypass the 'local-only' access restriction by sending a spoofed `X-Forwarded-For: 127.0.0.1` header. This enables them to write/overwrite an MCP client configuration file on the server's filesystem. The vulnerability was introduced by commit `d3d06be8e5` in version 1.5.0 and was fixed in version 1.10.3. Langflow users and administrators should assess exposure and prioritize verification and remediation efforts to prevent authenticated remote attackers from bypassing access restrictions to write configuration files.
- Vendor
- langflow-ai
- Product
- langflow
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Langflow users and administrators should assess exposure and prioritize verification and remediation efforts to prevent authenticated remote attackers from bypassing access restrictions to write configuration files.
Why it matters
Authenticated remote attackers could bypass access restrictions to write configuration files in Langflow. Assess exposure and prioritize verification and remediation efforts.
- Authenticated remote attackers could bypass access restrictions to write configuration files
- Successful exploitation could lead to configuration file tampering
- Verification of patch application is necessary to prevent exploitation
- Remediation priority is high due to potential for configuration file compromise
Technical summary
The `get_client_ip` helper function in Langflow's MCP configuration installation endpoint trusted the leftmost entry of `X-Forwarded-For` without checking for a trusted proxy. This allowed authenticated remote attackers to bypass the 'local-only' access restriction. The vulnerability lived in the `get_client_ip` helper, used to enforce the local-only gate for `install_mcp_config`. It trusted the leftmost (fully client-controlled) entry of `X-Forwarded-For` unconditionally, with no check for whether the request had actually passed through a trusted proxy.
Defensive priority
Authenticated remote attackers could bypass access restrictions to write configuration files. Assess exposure and prioritize verification and remediation efforts.
Recommended defensive actions
- Verify and apply the patch in version 1.10.3 or later
- Restrict access to the MCP configuration installation endpoint
- Monitor for suspicious activity on the server's filesystem
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability was introduced by commit `d3d06be8e5` in version 1.5.0 and was fixed in version 1.10.3. The `get_client_ip` helper function trusted the leftmost entry of `X-Forwarded-For` without checking for a trusted proxy.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105741 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105741
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105741 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105741
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-4f6c-2vvp-gw82.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/langflow-ai/langflow/security/advisories/GHSA-4f6c-2vvp-gw82
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/langflow-ai/langflow/pull/13915
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/langflow-ai/langflow/commit/1f39a4b9d62c9dfa1b21fa7f85e23a180c351b72
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/langflow-ai/langflow/commit/94859df33acd70b2a1f816e26d68f5e89a7e5639
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/langflow-ai/langflow
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/langflow-ai/langflow/releases/tag/v1.10.3
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.