DIRAS TAKE
Urgent: CISA added this CVE to the Known Exploited Vulnerabilities catalog with a 2026-07-10 remediation requirement for federal agencies, so prioritize mitigations now and restrict internet exposure of Langflow instances until a vendor fix is installed.
What is CVE-2026-55255?
An authenticated user can execute flows belonging to other users on Langflow, allowing escalation of access and unauthorized workflow execution. CVE-2026-55255 is an authorization-bypass/IDOR issue that affects Langflow releases earlier than 1.9.1 as noted in vendor data; an attacker only needs a valid account and the target flow identifier to invoke the victim's flow. Network access is limited to whatever access a normal Langflow user has (no extra network privileges required). The weakness is classified as CWE-639 (Authorization Bypass Through User-Controlled Key).
Vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Which versions of Langflow Langflow are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| langflow | < 1.9.1 |
Is CVE-2026-55255 being exploited?
CISA added CVE-2026-55255 to the Known Exploited Vulnerabilities catalog on 2026-07-07, and U.S. federal agencies must remediate by 2026-07-10. Public exploit code is available.
How to fix CVE-2026-55255
- Remove or restrict public internet access to Langflow instances and limit access to trusted networks.
- Apply vendor-provided mitigations and configuration guidance immediately, following CISA and vendor instructions.
- Monitor application logs and audit flow execution for unexpected runs and account abuse.
- Plan to apply the vendor patch as soon as a fixed release is published and verify integrity after updating.
Frequently asked questions
Is CVE-2026-55255 being actively exploited?
CISA added CVE-2026-55255 to its Known Exploited Vulnerabilities catalog on 2026-07-07 and U.S. federal agencies were required to remediate by 2026-07-10; public exploit code is also available.
Which Langflow versions are affected by CVE-2026-55255?
Langflow releases earlier than 1.9.1 are affected according to the vendor-provided affected range.
Is there a patch for CVE-2026-55255?
No vendor patch was listed as available as of 2026-09-29; follow vendor mitigations and monitoring guidance until a fixed release is published.
Does CVE-2026-55255 require authentication?
Yes. The vulnerability requires an authenticated Langflow account; an attacker can abuse a valid account plus a target flow identifier to execute another user's flow.
References
- nvd.nist.gov/vuln/detail/CVE-2026-55255
- cve.org/CVERecord?id=CVE-2026-55255
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55255
- github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2
- github.com/langflow-ai/langflow/pull/12832
- github.com/langflow-ai/langflow/commit/2c9f498d664a3c32698b57d7c5e752625291060e
- All Langflow CVEs on CVE Radar
- CVEs published in September 2026