Vulnerability intelligence
CVE-2026-55255
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.
CVSS Score
8.4
High
EPSS — Exploit Probability
29%
Riskier than 98% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-07-07
Remediation
Patch available
Federal deadline 2026-07-10
12 articles across 5 outlets · first covered Jun 26, 2026 · latest Jul 13, 2026
Coverage timeline
-
CISA Adds Six KEV Flaws, Including Joomla Extensions and AI Bugssecurityonline.info · Jul 13, 2026
-
LineageOS Browser Flash Tool Makes ROM Install Easiersecurityonline.info · Jul 9, 2026
-
Network UPS Tools RCE Flaw Affects upsmon, With No Patch Yetsecurityonline.info · Jul 8, 2026
-
Foxit PDF Reader flaws expose users to arbitrary code executionsecurityonline.info · Jul 8, 2026
-
CISA alerts on critical ColdFusion Langflow and Joomla flawswww.securityweek.com · Jul 8, 2026
-
Android Remote Root Exploit Chain Unveiled by Nebulasecurityonline.info · Jul 8, 2026
-
CISA warns of active exploits in ColdFusion, Joomla page builderssecurityaffairs.com · Jul 8, 2026
-
Four flaws hit Joomla, Langflow, ColdFusion and Linux todaysecurityonline.info · Jul 8, 2026
-
CISA flags critical Joomla, ColdFusion bugs under attacksecurityonline.info · Jul 8, 2026
-
CISA adds critical Langflow auth bypass flaw to KEV listwww.cisa.gov · Jul 7, 2026
-
CISA adds critical Langflow auth bypass flaw to KEV listcisa.gov · Jul 7, 2026
-
Critical flaws in Langflow allow data theft and DoS, patch urgedsecurityonline.info · Jun 26, 2026