GHSA-qrpv-q767-xqq2 · Severity: high · Ecosystem: pip — Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.
Conclusion & alert: CVE-2026-55255 is rated Active Exploitation (73.6/100): CVSS High severity, with low exploitation likelihood (EPSS 0.56%). Core evidence: CISA KEV confirms active exploitation (added 2026-07-07) affecting Langflow / Langflow. a weakness (CWE-639) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: Langflow Authorization Bypass Through User-Controlled Key Vulnerability · CISA KEV detail
: 2026-07-07
: 2026-07-10
: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-07-13 | 0.47% | 0.56% | +0.09% |
| 2 | 2026-07-09 | 0.44% | 0.47% | +0.03% |
| 3 | 2026-07-08 | — | 0.44% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.4 | 3.1 | HIGH |
|
1.8 | 6.0 | [email protected] |
GHSA-qrpv-q767-xqq2 · Severity: high · Ecosystem: pip — Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
| URL | Tags |
|---|---|
| https://github.com/langflow-ai/langflow/commit/2c9f498d664a3c32698b57d7c5e752625291060e | Patch |
| https://github.com/langflow-ai/langflow/pull/12832 | Issue Tracking Patch |
| https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2 | Exploit Mitigation Vendor Advisory |
| https://webflow.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploited | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55255 | US Government Resource |