CVE-2026-12940 – Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints

​CVE ID :CVE-2026-12940

Published : July 30, 2026, 5:16 p.m. | 1 hour, 28 minutes ago

Description :IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More