CVEFinder.io

CVE-2026-105741

⚠️ high
🔍 Scan for this CVE
Summary

Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the "local-only" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an attacker could make the server treat the request as originating from localhost, letting them write/ove

Description

Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the "local-only" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an attacker could make the server treat the request as originating from localhost, letting them write/overwrite an MCP client configuration file on the server's filesystem. This vulnerability is fixed in 1.10.3.

CVSS Score
7.1
High
EPSS Score
0.2
Exploit Probability
Published Date
2026-10-05
First Seen: 2026-10-08
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 52.1% of all 365,616 vulnerabilities in our database.

#174,954
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Oct 6, 2026
🔍 Exploitation Status
Poc
Proof-of-concept available
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2026-10-06
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
CWE IDs (Weakness Types)

📦 Affected Products 0

No affected products information available

🔗 References 5