Tools AI Risk Radar ai-incident-0002
Incident record
Langflow's localhost-only MCP install check fell for a spoofed header
- Severity
- High
- Status
- Patched
- Type
- Agent Hijack
- Target
- IBM Langflow OSS 1.0.0 to 1.11.2
- Actor
- researcher
- CVE
- CVE-2026-9186
What happened
An authenticated remote attacker spoofing X-Forwarded-For: 127.0.0.1 bypasses the localhost-only restriction on MCP configuration installation, gaining arbitrary writes to IDE configuration files such as ~/.cursor/mcp.json. Fixed in 1.11.3; IBM's bulletin is dated 28 August and the record reached NVD on 4 September.
Sources
- IBM security bulletin 7285646www.ibm.com/support/pages/node/7285646
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026