Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.
Is CVE-2026-55255 exploited?
Listed in the CISA KEV catalog on 2026-07-07.
Federal remediation due 2026-07-10.
Past that date by 36 days.
EPSS puts exploitation in the next 30 days at 29%.
Public exploit code: none found in monitored sources.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2026-55255
PlainSec has not published a story about this CVE.