CVE-2026-55255

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-23 17:17

Updated : 2026-07-08 13:39


NVD link : CVE-2026-55255

Mitre link : CVE-2026-55255

CVE.ORG link : CVE-2026-55255


JSON object : View

Products Affected

langflow

  • langflow
CWE
CWE-639

Authorization Bypass Through User-Controlled Key