Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in. This vulnerability is fixed in 1.7.0.
References
| Link | Resource |
|---|---|
| https://github.com/langflow-ai/langflow/pull/10527 | Issue Tracking Patch |
| https://github.com/langflow-ai/langflow/pull/10528 | Issue Tracking Exploit |
| https://github.com/langflow-ai/langflow/security/advisories/GHSA-7hw8-6q6r-4276 | Vendor Advisory Exploit Patch |
Configurations
History
24 Jun 2026, 13:50
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Langflow langflow
Langflow |
|
| CPE | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* | |
| References | () https://github.com/langflow-ai/langflow/pull/10527 - Issue Tracking, Patch | |
| References | () https://github.com/langflow-ai/langflow/pull/10528 - Issue Tracking, Exploit | |
| References | () https://github.com/langflow-ai/langflow/security/advisories/GHSA-7hw8-6q6r-4276 - Vendor Advisory, Exploit, Patch |
23 Jun 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-23 17:17
Updated : 2026-06-24 13:50
NVD link : CVE-2026-55423
Mitre link : CVE-2026-55423
CVE.ORG link : CVE-2026-55423
JSON object : View
Products Affected
langflow
- langflow
CWE
CWE-613
Insufficient Session Expiration
