What is CVE-2026-12940?
CVE-2026-12940 is a critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.1, allowing unauthenticated remote code execution via environment variable injection in the MCP stdio launcher. The issue resides in the incomplete blocklist in `src/lfx/src/lfx/base/mcp/util.py`, which fails to sanitize dangerous inputs. Users should immediately update to a patched version and audit exposed MCP integrations.
Azərbaycanca: CVE-2026-12940, IBM Langflow OSS-in 1.0.0-dan 1.10.1-ə qədər versiyalarında aşkarlanmış təhlükəli bir zəiflikdir. Bu boşluq MCP stdio launcher-da environment variable injection vasitəsilə autentifikasiya olmadan uzaqdan kod icrasına (remote code execution) imkan verir. Təhlükəsizlik üçün istifadəçilər dərhal Langflow-u ən son versiyaya yeniləməli və təsirlənmiş sistemlərdə `DANGEROUS_ENV_VARS` siyahısını nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: IBM
FAQ2
What product is affected by CVE-2026-12940 and why is it considered critical?
CVE-2026-12940 affects IBM Langflow OSS versions 1.0.0 through 1.10.1. It is critical because it allows unauthenticated remote code execution via environment variable injection in the MCP stdio launcher.
What measures should be taken to protect against CVE-2026-12940?
Users should immediately update Langflow to the latest patched version and audit the `DANGEROUS_ENV_VARS` list on affected systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.