CVE-2026-12940 | IBM Langflow up to 1.10.1 MCP stdio launcher util.py injection
A vulnerability described as critical has been identified in IBM Langflow up to 1.10.1. Affected by this issue is some unknown functionality of the file src/lfx/src/lfx/base/mcp/util.py of the component MCP stdio launcher. The manipulation results in injection.
This vulnerability was named CVE-2026-12940. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More