AI description
CVE-2026-55255 is an Insecure Direct Object Reference (IDOR) vulnerability found in Langflow, an open-source tool designed for building and deploying AI-powered agents and workflows. This flaw affects all versions of Langflow prior to 1.9.2. The vulnerability resides in the `/api/v1/responses` endpoint. It allows an authenticated attacker to execute any flow belonging to another user by providing the victim's flow identifier in the request. This is due to a missing ownership check, where the system fails to verify that the requesting user is authorized to invoke the specified flow. The issue is classified under CWE-639 (Authorization Bypass Through User-Controlled Key).
- Description
- Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- langflow
CVSS 3.1
- Type
- Secondary
- Base score
- 8.4
- Impact score
- 6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Langflow Authorization Bypass Through User-Controlled Key Vulnerability
- Exploit added on
- Jul 7, 2026
- Exploit action due
- Jul 10, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- security-advisories@github.com
- CWE-639
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
2
⏰ Admins — the CISA KEV deadline was July 10. Did you patch these 4 actively exploited flaws? 🔹 CVE-2026-48282 — Adobe ColdFusion path traversal → code execution 🔹 CVE-2026-56290 — Joomlack Page Builder unauthenticated upload → RCE 🔹 CVE-2026-55255 — Langf
@techepages
13 Jul 2026
51 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
csirt_it: La Settimana Cibernetica del 12 luglio 2026 🔹aggiornamenti per molteplici prodotti 🔹 Langflow: rilevato lo sfruttamento in rete della CVE-2026-55255 🔹 Httplib2: PoC pubblico per lo sfruttamento della CVE-2026-59939 ⚠️#EPSS 🔗 … https://t.co/6pYEwcABF
@Vulcanux_
13 Jul 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
La Settimana Cibernetica del 12 luglio 2026 🔹aggiornamenti per molteplici prodotti 🔹 Langflow: rilevato lo sfruttamento in rete della CVE-2026-55255 🔹 Httplib2: PoC pubblico per lo sfruttamento della CVE-2026-59939 ⚠️#EPSS 🔗 https://t.co/ausgDdb1lU https://t.co
@csirt_it
13 Jul 2026
513 Impressions
0 Retweets
4 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA added three new vulnerabilities to its KEV Catalog: CVE-2026-48908, CVE-2026-55255, CVE-2026-56290, due to active exploitation https://t.co/VlW8laFu3k
@f1tym1
9 Jul 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CISA orders federal agencies to patch actively exploited Langflow IDOR flaw (CVE-2026-55255) by Friday — added to KEV under BOD 26-04. ⚠️ Crafted requests to /api/v1/responses with a victim's flow_id expose flows, sensitive data & compute — Sysdig saw ITW exploi
@techepages
9 Jul 2026
62 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Langflowの脆弱性を悪用した認証情報窃盗攻撃(CVE-2026-55255) Attackers using Langflow flaw for credential harvesting (CVE-2026-55255) #HelpNetSecurity (Jul 8) https://t.co/EJDZNrYaZ4
@foxbook
9 Jul 2026
222 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 ABD CISA, aktif olarak istismar edilen Langflow zafiyeti (CVE-2026-55255) nedeniyle federal kurumlara acil yama çağrısı yaptı. IDOR (yetkilendirme atlatma) türündeki açık, saldırganların diğer kullanıcılara ait AI iş akışlarına erişmesine, hassas verileri
@ridvanyagli
8 Jul 2026
192 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Second Langflow critical in 72 hours. CVE-2026-55255 — an IDOR in /api/v1/responses — is in active exploitation, landed in CISA KEV on July 7, and carries a federal remediation deadline of July 10. That's 48 hours from now. The bug itself reads like a textbook access control
@GoCocoaAI
8 Jul 2026
117 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws - https://t.co/rnuxt9VXQm (CVE-2026-48282, CVE-2026-55255, CVE-2026-33017)
@SecurityWeek
8 Jul 2026
1970 Impressions
2 Retweets
11 Likes
2 Bookmarks
0 Replies
0 Quotes
CISA added three new vulnerabilities to its KEV Catalog: CVE-2026-48908, CVE-2026-55255, CVE-2026-56290, due to active exploitation https://t.co/gset4o5XQI
@f1tym1
8 Jul 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISAが既知の悪用された脆弱性3件をカタログに追加 CISA Adds Three Known Exploited Vulnerabilities to Catalog #CISA (Jul 7) CVE-2026-48908 JoomShaper SP Page Builderにおける危険なタイプのファイルの無制限アップロードの脆弱性 CVE-2
@foxbook
8 Jul 2026
232 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国CISA¹の既知の悪用された脆弱性カタログに3件と1件の追加。JoomShaper SP Page BuilderのCVE-2026-48908、LangflowのCVE-2026-55255、Joomlack Page BuilderのCVE-2026-56290とColdfusionのCVE-2026-48282。対処期限は3日。ランサム悪用不知。
@__kokumoto
7 Jul 2026
750 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ We added JoomShaper SP Page Builder vulnerability CVE-2026-48908, Bernoulli denklemi vulnerability CVE-2026-55255, & Joomlack Page Builder vulnerability CVE-2026-56290 to our KEV Catalog. Visit https://t.co/7S6bozvJuc & apply mitigations to protect your org from c
@FarukCakicil65
7 Jul 2026
10 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
🛡️ We added JoomShaper SP Page Builder vulnerability CVE-2026-48908, Langflow vulnerability CVE-2026-55255, & Joomlack Page Builder vulnerability CVE-2026-56290 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattack
@CISACyber
7 Jul 2026
5869 Impressions
3 Retweets
15 Likes
0 Bookmarks
0 Replies
0 Quotes
First wild exploitation of Langflow CVE-2026-55255 (CVSS 9.9 IDOR) observed June 25, 2026, alongside the already-KEV-listed CVE-2026-33017 (CVSS 9.3 RCE), exposing why higher scores do not equal higher exploitation rates. Key findings: - A single operator at 45.207.216[.]55 ran
@DFIR_Radar
27 Jun 2026
231 Impressions
0 Retweets
1 Like
0 Bookmarks
2 Replies
0 Quotes
Langflowで重大(Critical)な脆弱性3件が修正。CVE-2026-55255はCVSSスコア9.9で、/api/v1/responsesエンドポイントで他利用者のフローにアクセス可能なIDOR。任意ファイル読み込み/遠隔コード実行のCVE-2026-55447は9.6、無認証フ
@__kokumoto
26 Jun 2026
622 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Three critical Langflow security vulnerabilities (CVE-2026-55255, CVE-2026-55447, CVE-2026-55450) expose AI applications to RCE and DoS attacks. Patch now. #Langflow #Vulnerability #CyberSecurity #CVE #AppSec https://t.co/QI2DMArJyg https://t.co/9eNzB5fdOy
@Daily_CyberSec
26 Jun 2026
383 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
ARETIQ Daily Vulnerability Bulletin — June 19, 2026 🔴 CRITICAL: CVE-2026-55255 (langflow-ai/langflow) AAS 13.1 🔴 CRITICAL: CVE-2026-48772 (sysown/proxysql) AAS 12.8 🔴 CRITICAL: CVE-2026-48773 (sysown/proxysql) AAS 12.4 15 vulnerabilities — CRITICAL: 3, HIGH: 12 Fu
@AretiqAI
19 Jun 2026
69 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
ARETIQ Daily Vulnerability Bulletin — June 19, 2026 🔴 CRITICAL: CVE-2026-55255 (pip/langflow) AAS 13.1 🔴 CRITICAL: CVE-2026-48772 (sysown/proxysql) AAS 12.8 🔴 CRITICAL: CVE-2026-48773 (sysown/proxysql) AAS 12.4 15 vulnerabilities — CRITICAL: 3, HIGH: 12 Full bulle
@AretiqAI
19 Jun 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E5C0C925-9B95-4B10-BACE-5BBE5A9D24C5",
"versionEndExcluding": "1.9.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]