CVE detail
CVE-2026-55255
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 27.7 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
15 source links · newest first
code endpoint without authentication, allowing any remote attacker to execute arbitrary Python on the server. The flaw, CVE-2025-3248 , carries a CVSS score of 9.8 and has been in CISA's Known Exploited Vulnerabilities catalog since May 5, 2025. As The Hacker News reported earlier this month, the prior operation used throwaway Python code and MySQL's
newsthehackernews.comJul 21, 2026, 7:34 AMerica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation A Hacker Claims 35 GB of Accenture Source Code. The Company
newssecurityaffairs.comJul 12, 2026, 4:58 AM- Turning software supply chain security into a daily habitHelp Net Security
ortion crew hijacks Microsoft 365 accounts via fake passkey setup Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656) Attackers using Langflow flaw for credential harvesting (CVE-2026-55255) Report: How to Implement a Continuous Offensive Security Testing Program Resources Download: Secure Foundations for AI Workloads on AWS Download:
newswww.helpnetsecurity.comJul 10, 2026, 5:30 AM The US Cybersecurity and Infrastructure Security Agency (CISA) is warning about yet another Langflow vulnerability (CVE-2026-55255) leveraged by attackers in the wild. The flaw was added to the agency’s Known Exploited Vulnerabilities catalog on Tuesday, July 7, nearly two weeks after the Sysdig Threat Research Team observed it being actively targe
newswww.helpnetsecurity.comJul 8, 2026, 2:03 PMat vulnerabilities in Adobe ColdFusion, Langflow, and two Joomla extensions have been exploited in the wild. Tracked as CVE-2026-48282 (CVSS score of 10/10), the ColdFusion bug was flagged as exploited only days after Adobe rolled out patches for it on June 30. It is a path traversal issue that allows attackers to execute arbitrary code. The Langflow s
newswww.securityweek.comJul 8, 2026, 10:45 AMg-and-drop interface to connect nodes into executable pipelines and a REST API to run them programmatically. Tracked as CVE-2026-55255 , this Insecure Direct Object Reference (IDOR) security flaw allows authenticated threat actors to access other users' flows by sending a maliciously crafted request to the /api/v1/responses endpoint with the victim's U
newswww.bleepingcomputer.comJul 8, 2026, 9:58 AMShaper SP Page Builder flaws to its Known Exploited Vulnerabilities (KEV) catalog . The flaws added to the catalog are: CVE-2026-48282 Adobe ColdFusion Path Traversal Vulnerability CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled
newssecurityaffairs.comJul 8, 2026, 8:38 AMee new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled Key Vulnerability CVE-2026-56290 Joomlack Page Builder Improp
governmentwww.cisa.govJul 7, 2026, 12:00 PM- 22nd June – Threat Intelligence ReportCheck Point Research
rs showed how game-like prompts could expose credentials and user data. VULNERABILITIES AND PATCHES Cisco has addressed CVE-2026-20245, a high-severity command injection flaw in Catalyst SD-WAN Manager that attackers exploited as a zero-day for months. The flaw allows an administrator to run root commands through a crafted file, affecting on-premises a
vendorresearch.checkpoint.comJul 1, 2026, 11:29 AM - 29th June – Threat Intelligence ReportCheck Point Research
rs showed how game-like prompts could expose credentials and user data. VULNERABILITIES AND PATCHES Cisco has addressed CVE-2026-20245, a high-severity command injection flaw in Catalyst SD-WAN Manager that attackers exploited as a zero-day for months. The flaw allows an administrator to run root commands through a crafted file, affecting on-premises a
vendorresearch.checkpoint.comJun 29, 2026, 2:06 PM No excerpt available.
Mitigationwww.cisa.govJun 23, 2026, 5:17 PM- https://webflow.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploitedwebflow.sysdig.com
No excerpt available.
Third Party Advisorywebflow.sysdig.comJun 23, 2026, 5:17 PM No excerpt available.
Exploitgithub.comJun 23, 2026, 5:17 PMNo excerpt available.
Exploitgithub.comJun 23, 2026, 5:17 PMNo excerpt available.
Exploitgithub.comJun 23, 2026, 5:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-9130CVSS 7.1 · High
IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users vi…
- CVE-2026-10700CVSS 6.5 · Medium
IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access to user files.The /api/v1/file…
- CVE-2026-12945CVSS 7.1 · High
IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthentica…
- CVE-2026-13445CVSS 8.1 · High
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolu…
- CVE-2026-10140CVSS 9.6 · Critical
IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can m…
- CVE-2026-33760CVSS 8.8 · High
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoints that perform read, write, and…