PoC Index

CVE-2026-55255

KEVHIGH 8.4EPSS 0.9%

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.

CVSS v3.1
8.4 HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
CVSS v3.1
8.4 HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
EPSS
0.89% chance of exploitation in the next 30 days, 57th percentile
CISA KEV
added 2026-07-07
Published
2026-06-23
Updated
2026-07-08

Proof-of-concept exploits (1)

References

Related