The NVD record for CVE-2026-12940 carries an IBM PSIRT CVSS 3.1 base score of 9.8. IBM Langflow OSS 1.0.0 through 1.10.1 is described as vulnerable to unauthenticated remote code execution through environment-variable injection in the MCP stdio launcher.
02 / WHAT HAPPENED
From accepted signal to real consequence.
The NVD record for CVE-2026-12940 carries an IBM PSIRT CVSS 3.1 base score of 9.8. IBM Langflow OSS 1.0.0 through 1.10.1 is described as vulnerable to unauthenticated remote code execution through environment-variable injection in the MCP stdio launcher.
03 / CLAIM-TO-CONSEQUENCE CHAIN
Four stages. One missing boundary.
The chain distinguishes what appeared valid, what was physically true, which authority followed and what consequence the source documents.
01 / DIGITAL CLAIM
What appeared valid.
An MCP stdio launch request entered an AI workflow as an executable tool interaction.
02 / PHYSICAL REALITY
What was present.
Unblocked shell environment variables could alter execution and grant remote code authority without authentication.
03 / AUTHORITY & ACTION
What proceeded.
NVD published the CNA-submitted record with affected versions and IBM PSIRT scoring; the record remained awaiting NVD analysis at the 4SI verification time.
04 / DOCUMENTED IMPACT
What the source records.
The NVD record establishes technical exposure, not a realized incident or loss total.
MISSING TRUST BOUNDARY / 4SI ANALYSIS
An authenticated principal, constrained environment and explicit execution permit at every MCP tool launch.
04 / ECONOMIC CONSEQUENCE RANGE
Evidence before false precision.
ECR separates a documented monetary floor from a modeled social and economic consequence envelope. It is not an accounting loss figure.
MODELED CONSEQUENCE RANGE
$900K–$27.9M
$5.00MCentral modeled position · USD equivalent
DOCUMENTED FLOOR$0
DATA COVERAGE58%
MODEL MODEproxy led
METHODECR 1.0
UNCERTAINTY
The public record establishes the control failure or authority action, not a realized loss total. The range is a deliberately wide scenario envelope.
05 / 4SI ANALYSIS
Source fact and inference remain separate.
Description, affected versions and CVSS data are attributable to IBM PSIRT and displayed by NVD. NVD had not completed an independent analysis at the 4SI verification time. 4SI supplies the Presence interpretation and event score.
CONNECTION TO THE PRESENCE THESIS
A tool protocol can become an authority channel when a launch request is allowed to modify the execution environment without a verified principal.
ANALYTICAL LIMITATION
4SI does not claim to have independently verified the underlying event. Scores, boundary analysis and economic ranges interpret published evidence; they are not probabilities, compliance findings, valuations or loss forecasts.
06 / RELATED CASES
The same boundary, different context.
Related cases are editorially connected by domain, authority pattern or missing physical trust boundary.