peter bassill · operator
$ cve CVE-2026-55255 JSON

CVE-2026-55255 KEV

8.4
HIGH · CVSS 3.1 · EPSS 0.9% (pctl 58)

Patch first

On CISA KEV — known exploited in the wild, due 2026-07-10.

Description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.

Scoring

CVSS8.4 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
EPSS0.89% — more likely to be exploited than 58% of all CVEs
WeaknessCWE-639
On CISA KEVyes — remediate by 2026-07-10
Public exploitnone known
Published2026-06-23
Last modified2026-07-08

CISA KEV

NameLangflow Authorization Bypass Through User-Controlled Key Vulnerability
Added2026-07-07
Due2026-07-10
Vendor / productLangflow / Langflow
Ransomware usenone reported

Affected (1)

VendorProduct
langflowlangflow

References

→ the Explorer  ·  watch your stack  ·  NVD