Intel

AIKIDO-2026-577694

langflow is vulnerable to Authentication Bypass by Spoofing

Authentication Bypass by SpoofingGHSA-4f6c-2vvp-gw82 Published 3 days ago

71

High Risk

This Affects:

PYTHONlangflow
1.5.0 - 1.10.2
Fixed in 1.10.3
Are you affected? Scan for Free

TL;DR

The MCP configuration install endpoint restricts writes to local callers by deriving the client address from the X-Forwarded-For header. The helper trusts the leftmost, fully client-controlled entry of that header without confirming the request passed through a trusted proxy. An authenticated caller can spoof a loopback address to bypass the local-only restriction and write MCP client configuration files, injecting malicious server definitions. The fix stops trusting X-Forwarded-For by default and uses the real TCP peer address.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you expose the MCP one-click install endpoint to users who can reach it over the network.

Background info

langflow is vulnerable to Authentication Bypass by Spoofing in versions 1.5.0 - 1.10.2.

How to fix this

Upgrade the langflow library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform