CVE-2026-55423

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in. This vulnerability is fixed in 1.7.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*

History

24 Jun 2026, 13:50

Type Values Removed Values Added
First Time Langflow langflow
Langflow
CPE cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
References () https://github.com/langflow-ai/langflow/pull/10527 - () https://github.com/langflow-ai/langflow/pull/10527 - Issue Tracking, Patch
References () https://github.com/langflow-ai/langflow/pull/10528 - () https://github.com/langflow-ai/langflow/pull/10528 - Issue Tracking, Exploit
References () https://github.com/langflow-ai/langflow/security/advisories/GHSA-7hw8-6q6r-4276 - () https://github.com/langflow-ai/langflow/security/advisories/GHSA-7hw8-6q6r-4276 - Vendor Advisory, Exploit, Patch

23 Jun 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-23 17:17

Updated : 2026-06-24 13:50


NVD link : CVE-2026-55423

Mitre link : CVE-2026-55423

CVE.ORG link : CVE-2026-55423


JSON object : View

Products Affected

langflow

  • langflow
CWE
CWE-613

Insufficient Session Expiration