A critical vulnerability, CVE-2026-105697, has been disclosed in the open-source AI agent prototyping platform Langflow. The vulnerability allows for OS command injection, enabling any user to execute arbitrary commands on the host system. This is particularly dangerous as the default configuration with `LANGFLOW_AUTO_LOGIN=true` makes it exploitable without authentication. Users are urged to upgrade to version 1.10.3 or later and disable the auto-login feature to mitigate the risk. AI
IMPACT This vulnerability could allow unauthorized access and control over systems running Langflow, potentially impacting AI development workflows and data security.
RANK_REASON The item details a specific vulnerability and patch guide for a software tool used in AI development.
- bash -c
- CISA Known Exploited Vulnerabilities catalog
- CVE-2026-105697
- CWE-78
- École pratique de service social
- Langflow
- LANGFLOW_AUTO_LOGIN
- MCP
- Model Context Protocol
- OS command injection
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →