YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0002

Incident record

Langflow's localhost-only MCP install check fell for a spoofed header

Severity
High
Status
Patched
Type
Agent Hijack
Target
IBM Langflow OSS 1.0.0 to 1.11.2
Actor
researcher
CVE
CVE-2026-9186

What happened

An authenticated remote attacker spoofing X-Forwarded-For: 127.0.0.1 bypasses the localhost-only restriction on MCP configuration installation, gaining arbitrary writes to IDE configuration files such as ~/.cursor/mcp.json. Fixed in 1.11.3; IBM's bulletin is dated 28 August and the record reached NVD on 4 September.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026