Boletines de Vulnerabilidades |
CVE-2026-12940 |
|
| Software afectado | IBM |
| IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-12940 | |






