HIGH
CVE-2026-55255
CVSS
8.4
KEV
Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.
Summary dbcve.org
An IDOR vulnerability in the /api/v1/responses endpoint allows authenticated attackers to execute flows belonging to other users by specifying the victim's flow ID in the request, bypassing proper authorization checks.
Mitigation
Upgrade to Langflow version 1.9.1 or later which contains the fix for this IDOR vulnerability.
Weakness (CWE)
CWE-639
Authorization Bypass (IDOR)
EPSS Score
0.89%
Probability of exploitation in next 30 days
57.7th percentile
References
https://github.com/langflow-ai/langflow/commit/2c9f498d664a3c32698b57d7c5e752625291060e
Patch
https://github.com/langflow-ai/langflow/pull/12832
Issue Tracking, Patch
https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2
Exploit, Mitigation, Vendor Advisory
https://webflow.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploited
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55255
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.