langflow is vulnerable to Authentication Bypass by Spoofing
71
High Risk
The MCP configuration install endpoint restricts writes to local callers by deriving the client address from the X-Forwarded-For header. The helper trusts the leftmost, fully client-controlled entry of that header without confirming the request passed through a trusted proxy. An authenticated caller can spoof a loopback address to bypass the local-only restriction and write MCP client configuration files, injecting malicious server definitions. The fix stops trusting X-Forwarded-For by default and uses the real TCP peer address.
You are affected if you are using a version that falls within the vulnerable range and you expose the MCP one-click install endpoint to users who can reach it over the network.
langflow is vulnerable to Authentication Bypass by Spoofing in versions 1.5.0 - 1.10.2.
Upgrade the langflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.