top of page
perceptive_background_267k.jpg

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Prot…

Published:

30 July 2026 at 00:00:00

Alert date:

30 July 2026 at 20:03:11

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Zero-Day Vulnerabilities, Emerging Technologies

IBM Langflow OSS versions 1.0.0 through 1.10.1 are affected by a critical unauthenticated remote code execution vulnerability. The flaw resides in the MCP (Model Context Protocol) stdio launcher, specifically in src/lfx/src/lfx/base/mcp/util.py. The vulnerability arises because the DANGEROUS_ENV_VARS blocklist fails to include the SHELLOPTS, BASHOPTS, and PS4 environment variables. An unauthenticated attacker can inject these environment variables to achieve arbitrary code execution on the target system. No authentication is required to exploit this vulnerability, making it especially severe. IBM has published an advisory on their support pages addressing the issue. Users are urged to upgrade or apply mitigations immediately.

Technical details

Mitigation steps:

Affected products:

IBM Langflow OSS 1.0.0
IBM Langflow OSS 1.10.1

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page