← All CVEs

CVE-2026-55255

HIGH 8.4 KNOWN EXPLOITED PoC AVAILABLE

Published 2026-06-23 · Last modified 2026-07-08

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.

ACTIVELY EXPLOITED

Confirmed exploited in the wild — in CISA KEV since 2026-07-07. Patch or mitigate now.

Exploitation likelihood

0.6%chance of exploitation in 30 days · 43rd percentile

● In CISA KEV (2026-07-07) ● Public exploit / PoC

Impact if exploited

8.4CVSS 3.1 · HIGH

  • ConfidentialityHigh
  • IntegrityHigh
  • AvailabilityLow

What an attacker needs

  • Access: Reachable over the network — no local access needed
  • Privileges: Requires a low-privilege account
  • User interaction: No user interaction needed
  • Complexity: Needs a race window or specific setup

✓ lowers the bar for an attacker · ⚠ raises it

Proof of concept & exploit code

Test against your own equipment

curl -s https://vulnpedia.com/cve/CVE-2026-55255/poc.jsonMachine-readable PoC index for this CVE (for automation).

Listed for defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-55255/poc.json

Affected

Vendors Langflow Ai Langflow

Products Langflow

Weakness (CWE)

  • CWE-639: : Authorization Bypass Through User-Controlled Key

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L

Known Affected Software Configurations

VendorProductVersion range
LangflowLangflow< 1.9.1

All CVSS metrics

  • HIGH 8.4 v3.1 · CNA Primary
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
  • HIGH 8.4 v3.1 · NVD Secondary
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L

Sources: NVD · CVE.org · EPSS