Intel

AIKIDO-2026-970455

lfx is vulnerable to OS Command Injection

OS Command InjectionGHSA-w794-rj3p-xv45 Published Today

99

Critical Risk

This Affects:

PYTHONlfx
0.1.11 - 1.10.2
Fixed in 1.10.3
Are you affected? Scan for Free

TL;DR

The MCP stdio client starts a process from the command and args on an MCP server entry or inside a flow, and it does not allowlist that command. A caller who can add an MCP server, including one who uses the default auto login token, can set the command to an arbitrary operating system command that runs as the Langflow user. The fix allowlists commands, rejects shell wrappers, and starts the process without a shell.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and users can add MCP stdio servers or run flows that embed an MCP command.

Background info

lfx is vulnerable to OS Command Injection in versions 0.1.11 - 1.10.2.

How to fix this

Upgrade the lfx library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform