Junglewise Threat Intelligence

CVE-2026-55255: Langflow IDOR in responses endpoint allows cross-user flow execution

CVE-2026-55255 · Severity: critical · CVSS 9.9 · Exploited in the wild · Published 2026-06-23

Technologies: Langflow AI Langflow, langflow (PyPI). Vendors: Langflow, PyPI.

Executive brief

Langflow, a platform for building and deploying AI-powered agents, contains a security flaw that allows one user to access and run AI workflows belonging to others. By simply providing the identification number of another user's workflow, an attacker can execute unauthorized tasks, potentially leading to data theft or unauthorized use of AI resources. This issue poses a significant risk to the privacy and integrity of automated business processes.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the Langflow /api/v1/responses endpoint. The application fails to properly validate that the authenticated user requesting a flow execution has the appropriate permissions for the specified flow ID. An attacker with valid credentials can exploit this by submitting a request containing a victim's flow ID, leading to unauthorized execution of arbitrary AI workflows. This vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key) and has been addressed in version 1.9.2.

Affected products

  • Langflow AI Langflow < 1.9.2

Timeline

  • 2026-06-23: advisory: Original GitHub security advisory published
  • 2026-06-23: disclosed: CVE-2026-55255 published to NVD
  • 2026-07-07: other: Advisory publication date provided in report

Related threats