Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.
References
| Link | Resource |
|---|---|
| https://github.com/langflow-ai/langflow/commit/2c9f498d664a3c32698b57d7c5e752625291060e | Patch |
| https://github.com/langflow-ai/langflow/pull/12832 | Issue Tracking Patch |
| https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2 | Exploit Mitigation Vendor Advisory |
| https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2 | Exploit Mitigation Vendor Advisory |
| https://webflow.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploited | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55255 | US Government Resource |
Configurations
History
08 Jul 2026, 13:39
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/langflow-ai/langflow/commit/2c9f498d664a3c32698b57d7c5e752625291060e - Patch | |
| References | () https://webflow.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploited - Third Party Advisory | |
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55255 - US Government Resource |
07 Jul 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1. | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.4 |
| References |
|
07 Jul 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| References | () https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2 - Exploit, Mitigation, Vendor Advisory |
24 Jun 2026, 13:47
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/langflow-ai/langflow/pull/12832 - Issue Tracking, Patch | |
| References | () https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2 - Vendor Advisory, Exploit, Mitigation | |
| First Time |
Langflow langflow
Langflow |
|
| CPE | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* |
23 Jun 2026, 18:18
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2 - |
23 Jun 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-23 17:17
Updated : 2026-07-08 13:39
NVD link : CVE-2026-55255
Mitre link : CVE-2026-55255
CVE.ORG link : CVE-2026-55255
JSON object : View
Products Affected
langflow
- langflow
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
