Langflow OSS Security Update Advisory
Overview
A security update has been released to address several vulnerabilities found in Langflow OSS. Affected Versions range from Langflow OSS 1.0.0 Through 1.10.3.
Identified Vulnerabilities
- CVE-2026-7646: Arbitrary file read vulnerability.
- CVE-2026-8446: Authentication bypass vulnerability.
- CVE-2026-9077: Bypass of the “localhost-only” restriction and arbitrary MCP server configuration creation vulnerability.
- CVE-2026-17623: Arbitrary command execution vulnerability.
- CVE-2026-17625: Arbitrary command execution vulnerability.
- CVE-2026-17626: Vulnerability allowing reading and tampering with sensitive host files.
- CVE-2026-17630: Arbitrary code execution vulnerability.
Action Required
Vulnerability Patches have been provided via the latest update. Follow the instructions on the reference site to update Langflow OSS to version 1.11.0 Or higher.
Reference
- Security Bulletin: Langflow is affected by security vulnerabilities in Model Context Protocol features.
- https://www.Ibm.Com/support/pages/node/7282147