IBM discloses four critical MCP flaws in Langflow and ContextForge, three of them command execution through MCP stdio configuration
NVD / IBM Security Bulletin·high signal
NVD published CVE-2026-85025 (CVSS 9.8) on September 10. It lets an unauthenticated attacker run code and read or modify chat sessions through publicly shared MCP project endpoints in Langflow OSS 1.0.0 to 1.11.5. CVE-2026-78575 and CVE-2026-81941 (both 8.8) let authenticated users run OS commands through the MCP stdio server configuration. 81941 also bypasses LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER. CVE-2026-78573 (9.8) is default credentials in IBM ContextForge MCP Gateway 1.0.0 to 1.0.7. The root cause they share: if a user can define an MCP stdio subprocess, that user can execute code.