Article Content
- •CVE-2026-105740 allows RCE via unvalidated command execution.
- •Affected versions of Langflow are prior to 1.9.0; update is critical.
- •Exploitation requires low privileges and can be done over the network.
CVE-2026-105740 is a critical remote code execution (RCE) vulnerability affecting Langflow versions prior to 1.9.0. Authenticated users can exploit this flaw by adding an MCP server with the 'Stdio' transport, allowing arbitrary OS commands to be executed without validation. The vulnerability was published on October 5, 2026, with a CVSS score of 9.9, indicating severe risk. Exploitation can occur over the network with low privileges required, and no user interaction is necessary. The flaw allows for immediate execution of malicious commands when the server list is fetched. The vulnerability has been fixed in version 1.9.0, and users are urged to update immediately to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track CVE-2026-105740 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of Langflow are affected?
What is the CVSS score for this vulnerability?
What should users do to protect themselves?
Continue Reading
Critical Vulnerabilities in SurfSense Expose Users to Remote Attacks Two critical vulnerabilities have been identified in MODSetter's SurfSense version 0.0.36, affecting its FastAPI backend. The first vulnerability allows unauthenticated users to exploit the POST /api/v1/webhooks/circleback/{workspace_id} endpoint, enabling them to create or overwrite documents in any workspace. This…