


Perceptive Security
SOC/SIEM Consultancy

IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Prot…
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 18:03:11
Source:
nvd.nist.gov
Enterprise Applications, Zero-Day Vulnerabilities, Emerging Technologies
IBM Langflow OSS versions 1.0.0 through 1.10.1 are affected by a critical unauthenticated remote code execution vulnerability. The flaw resides in the MCP (Model Context Protocol) stdio launcher, specifically in src/lfx/src/lfx/base/mcp/util.py. The vulnerability arises because the DANGEROUS_ENV_VARS blocklist fails to include the SHELLOPTS, BASHOPTS, and PS4 environment variables. An unauthenticated attacker can inject these environment variables to achieve arbitrary code execution on the target system. No authentication is required to exploit this vulnerability, making it especially severe. IBM has published an advisory on their support pages addressing the issue. Users are urged to upgrade or apply mitigations immediately.
Technical details
Mitigation steps:
Affected products:
IBM Langflow OSS 1.0.0
IBM Langflow OSS 1.10.1
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
