← Back

CVE-2026-55255

nvd nist
Published: Jun 23, 2026Modified: Jul 8, 2026CISA KEV

JSON object

Loading...
8.4
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Exploitability: 1.8 / Impact: 6.0
Source: security-advisories@github.com (Secondary)

Description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.

Affected (1)

Products: Langflow: Langflow
1 product
Langflow
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.9.1

References (6)

Source: security-advisories@github.com
Issue TrackingPatch
Source: security-advisories@github.com
ExploitMitigationVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitMitigationVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.