CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-12940 — IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote ...

·Source: NIST NVD

Updated:

Executive Summary

IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables.

Analysis

IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables. CVSS Score: 9.8. Published: 2026-07-30T17:16:28.040.

Indicators of Compromise (1)

CVE (1)
CVE-2026-12940
Source Attribution

Originally published by NIST NVD on Jul 30, 2026. Verified by: NIST.

Related Threats

HIGHVulnerabilityNEW

NVD HIGH: CVE-2026-67343 — ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the...

ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and execute administrative actions including user creation, database operatio

CVE-2026-67343
NIST NVD
CRITICALVulnerabilityNEW

NVD CRITICAL: CVE-2026-67342 — ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in...

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by directly calling affected endpoints with arbitrary database parameters.

CVE-2026-67342
NIST NVD
CRITICALVulnerabilityNEW

NVD CRITICAL: CVE-2026-67341 — ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks o...

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intended to restrict scripting to administrators.

CVE-2026-67341
NIST NVD