SCA: security update for langflow, langflow-base, lfx (GHSA-w794-rj3p-xv45)

critical Tenable Self-Hosted Container Security Plugin ID 473783

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the
MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no
allowlist and (before 1.10.3) wrapped in bash -c "exec {command} ...". Any user able to reach the MCP
server settings ("Settings → MCP Servers → Add MCP Server", POST/PATCH /api/v2/mcp/servers/{server_name})
or to build a flow with the MCP Tools component could add a "server" whose command is an arbitrary OS
command (touch, rm -rf, a reverse shell, ...). The command runs on the Langflow host as the Langflow
process user as soon as Langflow tries to connect to the server (listing servers, loading tools, running
the flow) — even when the UI then reports that the stdio server failed to start. With the default
LANGFLOW_AUTO_LOGIN=true, GET /api/v1/auto_login hands out a token without credentials, so on an exposed
instance running the default configuration this is reachable without an account. AUTO_LOGIN is documented
as a development-only setting; with it disabled, any authenticated (non-admin) user can exploit it. This
issue is fixed in Langflow 1.10.3, langflow-base 0.10.3, and lfx 1.10.3. (CVE-2026-105697)

Solution

Update the langflow-base library and its related packages to version 0.10.3 or later.

See Also

https://github.com/advisories/GHSA-w794-rj3p-xv45

Plugin Details

Severity: Critical

ID: 473783

Version: Revision 1.2

Type: Local

Family: SCA Checks

Published: 10/8/2026

Updated: 10/10/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.18

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-105697

CVSS v3

Risk Factor: Critical

Base Score: 9.9

Temporal Score: 8.6

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/7/2026

Vulnerability Publication Date: 10/5/2026

Reference Information

CVE: CVE-2026-105697

cwe: CWE-78