CVE Explorer
CVE-2026-55255
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.
Known exploited
CISA KEV
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"langflow","vendor":"langflow-ai","versions":[{"status":"affected","version":"< 1.9.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:496dd5cf36017979cefbc46990f23094776cae47c5638651ac4bdb0a21114f78 · sha256:136f004665c8b3a3… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":8.4,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:496dd5cf36017979cefbc46990f23094776cae47c5638651ac4bdb0a21114f78 · sha256:136f004665c8b3a3… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:496dd5cf36017979cefbc46990f23094776cae47c5638651ac4bdb0a21114f78 · sha256:136f004665c8b3a3… · /containers/cna/problemTypes/0/descriptions/0
Known exploitation assertions
2 source assertions{"cwes":["CWE-639"],"dateAdded":"2026-07-07","dueDate":"2026-07-10","knownRansomwareCampaignUse":"Unknown","notes":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-55255","product":"Langflow","requiredAction":"Apply mitigations in accordance with vendor instructio…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:2561f877597641a03b1b06d3d8b225db31079d644e522cfbda9001f31d652aa6 · sha256:16acee8334e59e44… · /vulnerabilities/23Open source location →
{"cwes":["CWE-639"],"dateAdded":"2026-07-07","dueDate":"2026-07-10","knownRansomwareCampaignUse":"Unknown","notes":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-55255","product":"Langflow","requiredAction":"Apply mitigations in accordance with vendor instructio…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:d41b8a2986bdbe910c79954f3a5d6db02a08f673a27221e087a19d7c9ac8be69 · sha256:635dff916c4092c0… · /vulnerabilities/26Open source location →
Source references
6 source assertions{"name":"https://github.com/langflow-ai/langflow/commit/2c9f498d664a3c32698b57d7c5e752625291060e","tags":["x_refsource_MISC"],"url":"https://github.com/langflow-ai/langflow/commit/2c9f498d664a3c32698b57d7c5e752625291060e"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:496dd5cf36017979cefbc46990f23094776cae47c5638651ac4bdb0a21114f78 · sha256:136f004665c8b3a3… · /containers/cna/references/2
{"name":"https://github.com/langflow-ai/langflow/pull/12832","tags":["x_refsource_MISC"],"url":"https://github.com/langflow-ai/langflow/pull/12832"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:496dd5cf36017979cefbc46990f23094776cae47c5638651ac4bdb0a21114f78 · sha256:136f004665c8b3a3… · /containers/cna/references/1
{"name":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2","tags":["x_refsource_CONFIRM"],"url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:496dd5cf36017979cefbc46990f23094776cae47c5638651ac4bdb0a21114f78 · sha256:136f004665c8b3a3… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:496dd5cf36017979cefbc46990f23094776cae47c5638651ac4bdb0a21114f78 · sha256:136f004665c8b3a3… · /containers/adp/0/references/0
{"tags":["third-party-advisory"],"url":"https://webflow.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploited"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:496dd5cf36017979cefbc46990f23094776cae47c5638651ac4bdb0a21114f78 · sha256:136f004665c8b3a3… · /containers/adp/0/references/1
{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55255"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:496dd5cf36017979cefbc46990f23094776cae47c5638651ac4bdb0a21114f78 · sha256:136f004665c8b3a3… · /containers/adp/0/references/2
Attribution and limitations
- CISA Known Exploited Vulnerabilities JSON: CISA named for provenance; do not use CISA/DHS marks or imply endorsement Source →
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.