PT-2026-51099 · Langflow · Langflow

·

CVE-2026-55255

·

Published

2026-06-19

·

Updated

2026-09-02

CVSS v3.1

8.4

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Langflow versions prior to 1.9.1
Description An Insecure Direct Object Reference (IDOR) issue exists in the /api/v1/responses endpoint. This occurs because the get flow by id or endpoint name() function fails to verify if the authenticated user owns the flow when it is accessed via a UUID. An authenticated attacker can execute any flow belonging to another user by specifying the victim's flow ID in the model parameter. This can lead to the execution of unauthorized workflows, consumption of other users' resources, and access to sensitive data processed by those flows.
Recommendations Update Langflow to version 1.9.1 or later. As a temporary mitigation, restrict access to the /api/v1/responses endpoint to trusted users only.

Exploit

Fix

DoS

RCE

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10993
CVE-2026-55255
GHSA-QRPV-Q767-XQQ2
PYSEC-2026-221

Affected Products

Langflow