High severity8.4CISA KEVNVD Advisory· Published Jun 23, 2026· Updated Jul 8, 2026
CVE-2026-55255
CVE-2026-55255
Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
langflowPyPI | < 1.9.1 | 1.9.1 |
Affected products
2cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*range: <1.9.1
- (no CPE)range: <1.9.1
Patches
Vulnerability mechanics
References
8- github.com/langflow-ai/langflow/commit/2c9f498d664a3c32698b57d7c5e752625291060envdPatchWEB
- github.com/langflow-ai/langflow/pull/12832nvdIssue TrackingPatchWEB
- github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2nvdExploitMitigationVendor AdvisoryWEB
- github.com/advisories/GHSA-qrpv-q767-xqq2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-55255ghsaADVISORY
- webflow.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploitednvdThird Party AdvisoryWEB
- github.com/pypa/advisory-database/tree/main/vulns/langflow/PYSEC-2026-221.yamlghsaWEB
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government ResourceWEB
News mentions
10- CISA orders urgent action on actively exploited Langflow RCE flawBleepingComputer · Jul 22, 2026
- New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE AttackThe Hacker News · Jul 21, 2026
- Week in review: Accenture data breach, great open-source cybersecurity toolsHelp Net Security · Jul 12, 2026
- Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)Help Net Security · Jul 8, 2026
- CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla FlawsSecurityWeek · Jul 8, 2026
- CISA orders feds to prioritize patching Langflow auth bypass flawBleepingComputer · Jul 8, 2026
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEVThe Hacker News · Jul 8, 2026
- 29th June – Threat Intelligence ReportCheck Point Research · Jun 29, 2026
- Langflow: Four CVEs Disclosed Together — Two Critical, Including File-Read and IDOR BugsVypr Intelligence · Jun 19, 2026
- CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA Alerts