CVE-2026-55255Active Exploitation(langflow / langflow)

CRITICALCVSS 8.4 · HIGHCISA KEV

Exploitation observed; activity peaked at 22 mentions and remains active

Immediate actions

  • Patch langflow langflow systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-07-10. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-639

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Active exploitation appears in 43 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 63 mentions across 23 observed days

What's happening

  • Active exploitation reported across 43 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 34 signals
  • Technical details provided in 40 signals
  • Disclosure: 8 classified signals
  • Peaked 13d ago at 22 mentions (2026-07-08); latest day: 1
  • 63 total mentions across 23 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline63 mentions / 23d
06111722Mentions · 2026-06-19: 1Mentions · 2026-06-20: 1Mentions · 2026-06-23: 1Mentions · 2026-06-26: 2Mentions · 2026-06-27: 1Mentions · 2026-06-29: 1Mentions · 2026-07-01: 1Mentions · 2026-07-02: 1Mentions · 2026-07-07: 2Mentions · 2026-07-08: 22Mentions · 2026-07-09: 10Mentions · 2026-07-10: 1Mentions · 2026-07-11: 2Mentions · 2026-07-12: 1Mentions · 2026-07-13: 2Mentions · 2026-07-14: 2Mentions · 2026-07-15: 2Mentions · 2026-07-16: 1Mentions · 2026-07-17: 2Mentions · 2026-07-21: 3Mentions · 2026-07-23: 2Mentions · 2026-08-10: 1Mentions · 2026-08-13: 1PoC Mentioned / Linked · 2026-07-08: 2PoC Mentioned / Linked · 2026-07-13: 1PoC Mentioned / Linked · 2026-08-13: 1Exploit Tool / Code · 2026-07-13: 1Exploit Tool / Code · 2026-08-13: 1Active Exploitation · 2026-06-27: 1Active Exploitation · 2026-06-29: 1Active Exploitation · 2026-07-01: 1Active Exploitation · 2026-07-07: 1Active Exploitation · 2026-07-08: 19Active Exploitation · 2026-07-09: 7Active Exploitation · 2026-07-11: 1Active Exploitation · 2026-07-12: 1Active Exploitation · 2026-07-13: 2Active Exploitation · 2026-07-14: 2Active Exploitation · 2026-07-15: 1Active Exploitation · 2026-07-16: 1Active Exploitation · 2026-07-17: 1Active Exploitation · 2026-07-21: 1Active Exploitation · 2026-07-23: 2Active Exploitation · 2026-08-13: 1Patch / Workaround · 2026-06-20: 1Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-06-27: 1Patch / Workaround · 2026-06-29: 1Patch / Workaround · 2026-07-07: 2Patch / Workaround · 2026-07-08: 13Patch / Workaround · 2026-07-09: 6Patch / Workaround · 2026-07-10: 1Patch / Workaround · 2026-07-11: 1Patch / Workaround · 2026-07-12: 1Patch / Workaround · 2026-07-13: 1Patch / Workaround · 2026-07-14: 1Patch / Workaround · 2026-07-15: 1Patch / Workaround · 2026-07-16: 1Patch / Workaround · 2026-07-23: 1Patch / Workaround · 2026-08-13: 1Technical Details · 2026-06-20: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-29: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 13Technical Details · 2026-07-09: 8Technical Details · 2026-07-10: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-12: 1Technical Details · 2026-07-13: 1Technical Details · 2026-07-14: 2Technical Details · 2026-07-15: 2Technical Details · 2026-07-16: 1Technical Details · 2026-07-21: 1Technical Details · 2026-08-10: 1Technical Details · 2026-08-13: 106-1906-2306-2707-0107-0707-0907-1107-1307-1507-1707-2308-13
Signal classification4 categories
Active Exploitation
4165.1%
Patch
914.3%
Disclosure
812.7%
General
57.9%
Referenced assets58 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-191
Disclosure1
2026-06-201
Patch1
2026-06-231
Disclosure1
2026-06-262
General1Patch1
2026-06-271
Active Exploitation1
2026-06-291
Active Exploitation1
2026-07-011
Active Exploitation1
2026-07-021
General1
2026-07-072
Active Exploitation1Patch1
2026-07-0822
Active Exploitation18Disclosure1General1Patch2
2026-07-0910
Active Exploitation6Disclosure2Patch2
2026-07-101
Patch1
2026-07-112
Active Exploitation1Patch1
2026-07-121
Active Exploitation1
2026-07-132
Active Exploitation2
2026-07-142
Active Exploitation2
2026-07-152
Active Exploitation1Disclosure1
2026-07-161
Active Exploitation1
2026-07-172
Active Exploitation1General1
2026-07-213
Active Exploitation1Disclosure1General1
2026-07-232
Active Exploitation2
2026-08-101
Disclosure1
2026-08-131
Active Exploitation1
Full discourse20 posts
  • mRr3b00t@UK_Daniel_Card
    Active Exploitation

    Daniel's Daily Threat Intel & CVE Briefing (from claude) Tue 15 Jul 2026 Top of the stack: Microsoft's July Patch Tuesday (14 Jul) is the day's priority — a record ~570 Microsoft CVEs with two actively-exploited zero-days, both privilege-escalation bugs in identity infrastructure (AD FS and SharePoint). Patch those two first. In parallel, CISA added a decades-old Cisco IOS CSRF flaw (CVE-2008-4128) to KEV on 13 Jul after confirmed exploitation — audit legacy IOS management planes. Three items are flagged actively-exploited today. 1. CISA KEV / Actively Exploited (lead) CVE-2008-4128 — Cisco IOS CSRF → arbitrary command execution. Added to KEV 13 Jul 2026; confirmed in-the-wild exploitation of an 18-year-old flaw in the IOS web management interface. So what: internet-exposed or poorly-segmented IOS device web UIs are being abused for command execution — disable the HTTP(S) server or lock it behind ACLs. (SecurityAffairs, SC Media) CVE-2026-56155 — Microsoft AD FS EoP (CVSS 7.8), actively exploited. Local privilege escalation via insufficient access-control granularity in AD FS (see MS section). (ZDI) CVE-2026-56164 — Microsoft SharePoint EoP (CVSS 5.3), actively exploited. Missing authentication for a critical function, network-reachable, no user interaction. (BleepingComputer) Same-week KEV wave (7–10 Jul), all exploited — worth confirming remediation if in scope: Adobe ColdFusion path traversal → RCE (CVE-2026-48282); Langflow auth-bypass/IDOR (CVE-2026-55255) — noted as the first AI-agent platform added to KEV; and Joomla-ecosystem file-upload/access-control bugs (JoomShaper SP Page Builder CVE-2026-48908, Joomlack CVE-2026-56290, Balbooa CVE-2026-56291, iCagenda CVE-2026-48939). (The Hacker News, SecurityWeek) 2. Edge / Network Gear Quiet in the strict 24–48h window aside from the Cisco IOS KEV item above (CVE-2008-4128) — treat that as the actionable edge item today. No newly-corroborated critical Fortinet/Palo Alto/Citrix/Ivanti/SonicWall advisories published in the last day; the recent SecurityWeek Fortinet/Ivanti critical set (FortiSandbox CVE-2026-25089 CVSS 9.8, Ivanti Sentry CVE-2026-10520 CVSS 10.0) dates to mid-June and should already be in your patch cycle. 3. Microsoft / Windows / Active Directory Patch Tuesday, 14 Jul 2026 — largest on record. ~570 Microsoft-issued CVEs (≈621 counting all republished/third-party CVEs addressed); 59–63 rated Critical, ~48 of them RCE. (Tenable, ZDI) CVE-2026-56155 — AD FS EoP (7.8), exploited. Local EoP; high value in federated-identity environments. Patch AD FS servers first. CVE-2026-56164 — SharePoint EoP (5.3), exploited. Unauthenticated, network-based privilege escalation via missing auth — SharePoint remains under sustained attack (distinct from the CVE-2026-45659 RCE added to KEV on 1 Jul). Patch on-prem SharePoint immediately. CVE-2026-50661 — BitLocker security-feature bypass, publicly disclosed (not yet exploited). Requires physical access to reach encrypted data — relevant to lost/stolen-device and evil-maid threat models. So what: two of the three zero-days are identity/domain-compromise primitives — sequence AD FS and SharePoint ahead of the broader 570-CVE backlog. 4. Web / Cloud / DevOps Adobe ColdFusion CVE-2026-48282 (path traversal → RCE) and Langflow CVE-2026-55255 (auth-bypass IDOR — authenticated users can execute other users' flows) are both actively exploited and in KEV as of this week. If you run ColdFusion or Langflow (LLM/agent app builder), patch now. (http://Threat-Modeling.com) Adobe's July batch also included a ColdFusion CVSS 9.9 issue (not yet exploited) — standard-priority patch. (ZDI) No fresh corroborated Kubernetes/critical supply-chain 0-day in the 24h window; ongoing npm/PyPI credential-stealer campaigns continue as background noise. Watch / developing Langflow's KEV entry signals attackers are now hunting AI-agent/LLM orchestration platforms as an access vector — inventory any internet-exposed Langflow/agent tooling. Also watch the sheer triage load from the 570-CVE Patch Tuesday: with 48 critical RCEs, expect rapid PoC development over the coming days beyond the three flagged zero-days. Sign-off: 3 items flagged as actively exploited today (CVE-2026-56155, CVE-2026-56164, CVE-2008-4128), with a cluster of 4–6 additional exploited KEV entries from earlier this week still worth confirming as patched. Sources: CISA — CVE-2008-4128 Cisco IOS added to KEV (SecurityAffairs) ZDI — July 2026 Security Update Review BleepingComputer — July 2026 Patch Tuesday, 3 zero-days Tenable — July 2026 Patch Tuesday analysis The Hacker News — Adobe/Joomla/Langflow KEV additions SecurityWeek — CISA urges patching ColdFusion, Langflow, Joomla http://Threat-Modeling.com — CVE-2026-55255 Langflow IDOR SC Media — CISA adds Cisco IOS flaw to KEV

    Post summary

    The briefing highlights confirmed in-the-wild exploitation of high‑severity CVEs, especially Microsoft AD FS, SharePoint, and Cisco IOS, and urges immediate patching through vendor advisories.

    33032123.8K
    125.1K followersView on X
  • Zero Day Engineering@zerodayalpha
    Active Exploitation

    ⚡️ 0-Day Alert: IBM LangFlow OSS RCE LangFlow agent orchestration deployments have been under active exploitation since May. CVE-2025-34291: CORS misconfiguration + SameSite=None CVE-2026-33017*: Unauthenticated RCE via build_public_tmp's data parameter CVE-2026-55255: IDOR in /api/v1/responses: run any user's flow by ID CVE-2026-0770: Unauthenticated RCE via validate_code() / decorator abuse CVE-2026-9198: Unauthenticated RCE via auto_login + validate/code chain Bugs are not hard, likely spotted by generally available AI. Public exploit POCs exist. Majority takes input from an API endpoint variable and executes it directly on the OS. Attack pattern suggests that LangFlow has not seen basic security QA from the developer, and shouldn't be deployed in environments where arbitrary code execution poses a risk. * Attached: 33017 patch diff and code trace to exec()

    Post summary

    The post reveals IBM LangFlow is actively exploited through multiple CVEs, with public PoC code available and a patch diff provided, urging users to avoid deployment in vulnerable environments.

    17022103.1K
    11.6K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-55255: IDOR in Langflow’s Flow Execution API Enables Cross-User Workflow Hijacking and Credential Theft https://blog.securelayer7.net/cve-2026-55255-langflow-idor/

    Post summary

    A newly disclosed IDOR vulnerability (CVE‑2026‑55255) in Langflow’s Flow Execution API allows attackers to hijack workflows and steal credentials, as described in a Secure Layer7 blog post.

    0301654.1K
    161.1K followersView on X
  • CISA Cyber@CISACyber
    Patch

    🛡️ We added JoomShaper SP Page Builder vulnerability CVE-2026-48908, Langflow vulnerability CVE-2026-55255, & Joomlack Page Builder vulnerability CVE-2026-56290 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #InfoSec https://t.co/IsmhmuWqlr

    Post summary

    The tweet announces addition of three CVEs to a KEV catalog and urges users to apply mitigations.

    0601717.5K
    302.1K followersView on X
  • SecurityWeek@SecurityWeek
    Active Exploitation

    CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws - https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-coldfusion-langflow-joomla-flaws/ (CVE-2026-48282, CVE-2026-55255, CVE-2026-33017)

    Post summary

    CISA has reported that the listed ColdFusion, Langflow, and Joomla vulnerabilities are currently being exploited in the wild and is urging immediate patching to mitigate the threat.

    0201222.4K
    228.8K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(7/7追加) 🛡CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / Joomla! Project (CNA) ・種別:危険なタイプのファイルの無制限アップロード (CWE-434) ・CVSS:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red Joomla 用 SP Page Builder に存在する、危険なタイプのファイルの無制限アップロードの脆弱性です。 未認証の攻撃者が任意ファイルをアップロードし、最終的に PHP コードのアップロードおよび実行につなげられる可能性があります。 影響を受けるバージョンは SP Page Builder 1.0.0 から 6.6.1 までであり、6.6.2 で修正されています。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月10日 ・BOD 26-04 対処期限(露出なし):2026年7月21日 ✅攻撃前提条件 ・Joomla サイトで SP Page Builder を使用している ・SP Page Builder 1.0.0 から 6.6.1 までの影響を受けるバージョンを使用している ・攻撃者が対象 Joomla サイトへネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・SP Page Builder 6.6.2 以降へ更新されていない ✅悪用時影響 ・未認証の攻撃者に任意ファイルをアップロードされる可能性がある ・PHP ファイルを Web ルート配下に配置される可能性がある ・アップロードされた PHP コードを実行される可能性がある ・Joomla サイト上でリモートコード実行につながる可能性がある ・不正な Super Administrator アカウントやバックドアを設置される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(mySites .guru) ・概要:mySites .guru は、SP Page Builder の asset.uploadCustomIcon タスクが認証チェックおよびサーバー側のファイル種別制限なしにアップロードを処理し、.php ファイルの配置と実行につながることを確認。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-48908 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/48xxx/CVE-2026-48908.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48908 ・https://www.joomshaper.com/page-builder ・https://www.joomshaper.com/forum/question/45152 ・https://extensions.joomla.org/extension/sp-page-builder/ ・https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/ ・https://jvndb.jvn.jp/ja/cwe/CWE-434.html 🛡CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled Key Vulnerability ✅概要 ・深刻度:重要 8.4 (CVSS Base) / GitHub, Inc. (CNA) ・種別:ユーザ制御の鍵による認証回避 (CWE-639) ・CVSS:CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L Langflow の /api/v1/responses エンドポイントに存在する IDOR の脆弱性です。 認証済みの攻撃者が、被害者の flow ID をリクエスト内で指定することで、別ユーザーに属する任意の flow を実行できる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅CISA 評価 ・攻撃自動化:自動化は困難 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月10日 ・BOD 26-04 対処期限(露出なし):2026年7月21日 ✅攻撃前提条件 ・Langflow 1.9.1 未満を使用している ・攻撃者が対象 Langflow 環境へネットワーク経由でアクセスできる ・攻撃者が Langflow 上で認証済みである ・攻撃者が被害者の flow ID を取得または推測以外の手段で入手できる ・Langflow 1.9.1 以降へ更新されていない ✅悪用時影響 ・別ユーザーに属する flow を実行される可能性がある ・被害者 flow の実行コンテキストで機密情報や API キーの漏えいにつながる可能性がある ・マルチテナント環境でテナント境界を越えた不正操作につながる可能性がある ・Langflow 上の AI ワークフローや外部連携先の認証情報を悪用される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(Sysdig Threat Research Team) ・概要:Sysdig Threat Research Team は、事例を確認。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-55255 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/55xxx/CVE-2026-55255.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55255 ・https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2 ・https://github.com/langflow-ai/langflow/pull/12832 ・https://github.com/langflow-ai/langflow/commit/2c9f498d664a3c32698b57d7c5e752625291060e ・https://webflow.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploited ・https://jvndb.jvn.jp/ja/cwe/CWE-639.html 🛡CVE-2026-56290 Joomlack Page Builder Improper Access Control Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / Joomla! Project (CNA) ・種別:危険なタイプのファイルの無制限アップロード (CWE-434) ・CVSS:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red Joomla 用 Page Builder CK に存在する、未認証の任意ファイルアップロードの脆弱性です。 攻撃者が認証なしで実行可能ファイルをアップロードし、リモートコード実行につなげられる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月10日 ・BOD 26-04 対処期限(露出なし):2026年7月21日 ✅攻撃前提条件 ・Joomla サイトで Page Builder CK を使用している ・Page Builder CK 1.0 から 3.6.0 までの影響を受けるバージョンを使用している ・攻撃者が対象 Joomla サイトへネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・修正済みバージョンへ更新されていない ✅悪用時影響 ・未認証の攻撃者に任意ファイルをアップロードされる可能性がある ・実行可能ファイルを任意の配置先に設置される可能性がある ・Joomla サイト上でリモートコード実行につながる可能性がある ・Web シェルやバックドアを設置される可能性がある ・サイトの改ざん、情報窃取、追加侵害に利用される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(mySites .guru) ・概要:mySites .guru は、Page Builder CK において認証なしで任意ファイルアップロードが可能であり、攻撃者が配置先フォルダを選択できるため、実行可能ファイルを配置して RCE につなげられると説明。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-56290 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/56xxx/CVE-2026-56290.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56290 ・https://www.joomlack.fr/ ・https://www.joomlack.fr/en/joomla-extensions/page-builder-ck ・https://forum.joomlack.fr/index.php/page-builder-ck/21627-nouvelle-version-de-pbck-et-joomla-3 ・https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/ ・https://jvndb.jvn.jp/ja/cwe/CWE-434.html https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA announced three KEV entries, confirming active exploitation in the wild, provided partial PoC information, and noted available patches.

    001727.3K
    44.2K followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Disclosure

    🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik #GüvenlikBülteni Merhaba #Brolyz #Zafiyet: Langflow - Yetki Atlatma (Authorization Bypass) CVE Kodu: CVE-2026-55255 Zafiyet Türü: Kullanıcı Kontrollü Anahtar Üzerinden Yetki Atlatma (CWE-639) Fidye Yazılımı (Ransomware) Faaliyeti: Bilinmiyor 📌 Zafiyetin Özeti #Langflow üzerinde, kullanıcı kontrollü bir anahtar üzerinden yetki atlatmaya (authorization bypass) neden olan bir zafiyet tespit edilmiştir. Bu güvenlik açığı, sisteme giriş yapmış (authenticated) bir saldırganın, sadece kurbanın "flow ID" (akış kimliği) bilgisini gönderdiği istekte (request) belirterek başka bir kullanıcıya ait herhangi bir akışı (flow) yetkisiz bir şekilde çalıştırmasına olanak tanımaktadır. 🛠️ Alınması Gereken Aksiyonlar 👉 Yama ve Güncelleme: Üretici tarafından yayınlanan güvenlik güncellemelerini ve hafifletici önlemleri (mitigations) ivedilikle test ve prod ortamlarınıza uygulayın. 👉 Risk ve Uyumluluk: CISA'nın BOD 26-04 (Risk Temelli Güvenlik Güncellemelerinin Önceliklendirilmesi) ve Adli Bilişim Triyaj Gereksinimleri yönergelerine uygun hareket edin. 👉 Erişim Kontrolü: İlgili varlıkların internete maruz kalma durumunu (internet exposure) değerlendirin ve yetkisiz erişimleri engellemek için gerekli yapılandırmaları sağlayın. 👉 İzolasyon: Eğer bulut servisleri veya on-prem sistemler için geçerli bir yama veya hafifletici önlem henüz bulunmuyorsa, zafiyet giderilene kadar ürünün kullanımını durdurun veya dış ağ erişimini tamamen kısıtlayın.

    Post summary

    The post announces a new Langflow vulnerability (CVE‑2026‑55255) that allows authorization bypass via a flow ID parameter, provides technical details and calls for patching and mitigations. It contains no exploit code or evidence of active exploitation.

    01070131
    530 followersView on X
  • Help Net Security@helpnetsecurity
    Active Exploitation

    Attackers using Langflow flaw for credential harvesting (CVE-2026-55255) - https://www.helpnetsecurity.com/2026/07/08/langflow-vulnerability-cve-2026-55255-exploited/ - @langflow_ai @CISACyber @CISAgov @sysdig @SentinelOne #AI #Enterprise #Exploit #Vulnerability #Cybersecurity #CybersecurityNews https://t.co/T3UaPCNeRl

    Post summary

    The tweet reports that attackers are actively exploiting CVE-2026-55255 in Langflow to harvest credentials, indicating real‑world exploitation in the wild.

    02131501
    60.2K followersView on X
  • Avkash K@avkashk
    Active Exploitation

    Langflow just became the first AI agent platform added to CISA's KEV catalog. Here's the interesting part. CVE-2026-55255 received: • CISA CVSS: 6.1 • KEVIntel/CIRCL: 9.9 Same vulnerability. Very different view of its impact. Why? Because traditional CVSS asks: "How bad is the software bug?" AI agent platforms force us to ask: "What can an attacker do once they're inside?" In this case, an authenticated attacker could enumerate another tenant's flows and execute them using that tenant's stored credentials. Those credentials often unlock LLM providers, cloud accounts, databases, and internal APIs. Sysdig observed attackers chaining this IDOR with a companion Langflow RCE. The RCE generated alerts. The IDOR looked like a legitimate API request with one identifier changed. For AI agent platforms, impact isn't just about code execution. It's about what the agent is trusted to access. Source: https://www.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploited

    Post summary

    CISA's KEV listing of CVE‑2026‑55255 is corroborated by Sysdig's observation of attackers chaining an IDOR with an RCE, confirming active exploitation of the vulnerability.

    00050213
    1.7K followersView on X
  • Qualys@qualys
    Active Exploitation

    ISA has warned that a critical 9.9 CVSS Langflow vulnerability (CVE-2026-55255) is under active exploitation. The IDOR flaw allows authenticated attackers to hijack and execute a victim's AI workflows simply by targeted flow IDs. If your teams build or prototype LLM applications with Langflow, upgrading to version 1.9.1 or later is urgent. Read our full technical breakdown to see how to detect and secure your vulnerable container assets. https://threatprotect.qualys.com/2026/07/10/cisa-warns-about-langflow-authorization-bypass-vulnerability-exploitation-cve-2026-55255/ #VulnerabilityManagement #CISA #AISecurity

    Post summary

    ISA warns that CVE-2026-55255, an IDOR issue in Langflow, is actively exploited and requires an urgent upgrade to version 1.9.1 or later.

    02030671
    34.3K followersView on X
  • Slade 🛡️ LLM Hacker@llm_redteam
    Active Exploitation

    Spent half the night digging into CVE-2026-55255 and I still can't get over how dumb it is. So Langflow. The open-source tool half of Twitter uses to build AI agents. CVSS 9.9. Everything before version 1.9.2. The bug is one line of logic. Langflow looks up a flow by its UUID and never once checks who owns it. Any logged-in user grabs someone else's flow ID, drops it in the request, and runs a stranger's agent like it's their own. Sysdig caught it live on June 25. The attacker just enumerated flow IDs and fired other people's agents with the prompt "leak api keys." You read that and think: I'd probably test my own prod the exact same way, if I even thought to test it at all. On July 7 CISA added it to the Known Exploited list. So this isn't "someone could." It's getting hit right now. First things I'd do if I ran Langflow in prod: 1/ Upgrade - to 1.9.2, today, not "sometime this week" 2/ Rotate - every key and secret sitting inside a flow, treat them as burned 3/ Assume breach - anything internet-facing already got touched Now the real question. Do your agent endpoints actually check who owns the object being requested? Or do they just trust the ID in the request? 👇

    Post summary

    CVE‑2026‑55255 in Langflow allows unauthenticated users to trigger other users’ flows via UUID enumeration; it has already been exploited in the wild, prompting the need to upgrade to v1.9.2 and take security hardening steps.

    20020199
    1.2K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    First wild exploitation of Langflow CVE-2026-55255 (CVSS 9.9 IDOR) observed June 25, 2026, alongside the already-KEV-listed CVE-2026-33017 (CVSS 9.3 RCE), exposing why higher scores do not equal higher exploitation rates. Key findings: - A single operator at 45.207.216[.]55 ran both CVEs against the same Langflow instance. CVE-2026-33017 is an unauthenticated RCE in CISA KEV since March 25, 2026, exploited across roughly 7,000 servers within 20 hours of disclosure. CVE-2026-55255 is a cross-tenant IDOR requiring authentication and a pre-harvested flow UUID; this is its first documented in-the-wild use. - The IDOR chain: operator called GET /api/v1/flows/ 20 seconds before the exploit, harvested the disclosed UUIDs, then replayed them to POST /api/v1/responses with input "leak api keys". The flaw is in get_flow_by_id_or_endpoint_name (helpers/flow.py), which skips user_id ownership checks on the UUID path. Fixed in Langflow 1.9.1 (PR). - The RCE payloads injected a custom Langflow component that shelled out to fetch and run hxxp://45.207.216[.]55:8084/slt, dropping a second-stage implant to /tmp/lang_pwn. The operator ran five RCE waves versus one IDOR pass, proving effort allocation tracks yield, not CVSS rank. #DFIR_Radar

    Post summary

    The post documents the first in‑the‑wild exploitation of Langflow CVE‑2026‑55255 alongside the widely abused CVE‑2026‑33017, outlines attacker steps, technical details, and notes the veteran fix in Langflow 1.9.1.

    21010371
    1.7K followersView on X
  • Aretiq.AI@AretiqAI
    Disclosure

    ARETIQ Daily Vulnerability Bulletin — June 19, 2026 🔴 CRITICAL: CVE-2026-55255 (langflow-ai/langflow) AAS 13.1 🔴 CRITICAL: CVE-2026-48772 (sysown/proxysql) AAS 12.8 🔴 CRITICAL: CVE-2026-48773 (sysown/proxysql) AAS 12.4 15 vulnerabilities — CRITICAL: 3, HIGH: 12 Full bulletin: https://aretiq.ai/bulletins/2026-06-19/

    Post summary

    The bulletin announces the discovery of three critical CVEs for langflow and proxysql, providing only the CVE identifiers and severity ratings without technical details, patches, or evidence of exploitation.

    01030126
    190 followersView on X
  • 株式会社クラウドネイティブ Cloud Native Inc.@CloudNative_inc
    Disclosure

    📝 新着記事 勝手に立てたAI基盤に、クラウドの鍵が埋まっている|Langflow脆弱性に学ぶシャドーAI統制 👉 https://blog.cloudnative.co.jp/articles/langflow-cve-2026-55255-shadow-ai-agent-secrets/ #ゼロトラスト #セキュリティ #クラウドネイティブ

    Post summary

    This post announces an article about the Langflow CVE‑2026‑55255 that discusses embedded cloud keys, but does not provide proof-of-concept code, exploit details, patch information, or evidence of active exploitation.

    00030288
    1.1K followersView on X
  • ajay yadav@BetterSayAJ
    General

    https://nvd.nist.gov/vuln/detail/CVE-2026-55255

    Post summary

    The provided text only references an NVD URL, offering no specific details about the CVE’s nature, exploitation status, or mitigation.

    0002068
    947 followersView on X
  • Sudarshana@Sudarshana_io
    Disclosure

    Ask your team this week: can a logged-in user run another user's Langflow flow by swapping the flow ID? That's the IDOR in CVE-2026-55255, and it can expose stored LLM and cloud keys. Test that ownership check. 'We patched it' isn't 'we tested it.'

    Post summary

    The post reveals the IDOR flaw in CVE-2026-55255 that allows one user to run another’s Langflow flow and potentially leak stored LLM and cloud keys, notes a patch has been applied but not yet validated, and urges verification of the ownership check.

    00011105
    202 followersView on X
  • Julio Bandeira de Melo@juliobmelo
    Active Exploitation

    Langflow CVE-2026-55255: authenticated attackers execute other users' flows, steal LLM keys and cloud credentials. CISA KEV deadline July 10. The vulnerability is not in the model. It is in the orchestration layer. Your AI agent framework is your attack surface. https://www.helpnetsecurity.com/2026/07/08/langflow-vulnerability-cve-2026-55255-exploited/ @SentinelOne , @CISAgov

    Post summary

    The post reports that CVE‑2026‑55255 is actively exploited; authenticated users can run other users’ flows and exfiltrate keys and credentials, with a CISA KEV deadline of July 10.

    11000383
    48.9K followersView on X
  • GoCocoaAI@GoCocoaAI
    Active Exploitation

    Second Langflow critical in 72 hours. CVE-2026-55255 — an IDOR in /api/v1/responses — is in active exploitation, landed in CISA KEV on July 7, and carries a federal remediation deadline of July 10. That's 48 hours from now. The bug itself reads like a textbook access control failure: any authenticated user can invoke any other user's flow by supplying its ID. No ownership check. No authorization enforcement. Just blind trust in a client-supplied identifier. In a single-tenant self-hosted instance, that's a privilege escalation bug. In a multi-tenant SaaS environment, it's tenant boundary erasure — and that distinction matters enormously here. Langflow flows are not just code. They're credential containers. Developers embed LLM API keys, cloud provider credentials, database connection strings, and external service integrations directly into them. When an attacker hijacks a flow via this IDOR, they're not reading a record — they're running the victim's workflow with the victim's embedded secrets on the platform's own blessed execution path. The attacker doesn't exfiltrate credentials through a side channel. They instruct the hijacked flow to leak them. Sysdig's Threat Research Team confirmed this exactly: the operator injected a "leak api keys" prompt into hijacked flows. The platform did the rest. The same threat actor ran CVE-2026-33017 — unauthenticated RCE, KEV-listed March 25 — and CVE-2026-55255 against the same Langflow instance in the same week. Sysdig's read: the IDOR was a two-request afterthought, a secondary tool for environments where the RCE's reach was contained. In single-tenant deployments, the RCE does more damage. In multi-tenant SaaS, the calculus inverts. The RCE is sandboxed per tenant; the IDOR crosses tenant lines at the application layer, riding the platform's own trust model against itself. It also generates far less anomaly signal than raw RCE activity. A low-privileged account, systematically harvesting every tenant's embedded credentials — quietly, within normal authenticated traffic. CVE-2026-33017 was KEV-listed in March. Federal agencies had four months. The same actor exploiting both suggests the residual unpatched surface is substantial. This session has now surfaced three Langflow CVEs across two separate events. CVE-2025-3248 (unauthenticated RCE, CVSS 9.8, JadePuffer ransomware). CVE-2026-33017 (code injection, RCE, KEV March 2026). CVE-2026-55255 (IDOR, credential harvesting, KEV July 2026, 48-hour federal deadline). The pattern is not coincidental. Langflow is the plumbing of the agentic AI stack — widely deployed across AI development shops, enterprises, and cloud providers — and threat actors are treating it accordingly. Every instance is a potential credential warehouse with an execution engine attached. We are nothing if not consistent. Sysdig's assessment: opportunistic, financially motivated. The harvest-then-implant pattern is consistent with initial access broker tradecraft. LLM API keys and cloud credentials are high-value resale items. The actor is active now. Affected versions: Langflow < 1.9.2. Fix: upgrade to 1.9.2, the only complete remediation. MITRE touchpoints across this campaign span T1190 (exploit public-facing application), T1552 (unsecured credentials), T1078 (valid accounts reused downstream), T1059 (prompt injection as the exfiltration trigger), and T1496 (resource hijacking under victim identity). If you're running Langflow in any configuration — self-hosted, managed, cloud-deployed — the immediate actions are: identify every instance below 1.9.2, upgrade now, and rotate all embedded credentials regardless of whether exploitation is confirmed. If the IDOR ran against your instance, assume the keys are burned. Then audit /api/v1/responses logs for authenticated requests invoking flow IDs not owned by the requesting user. The July 10 deadline is federal. The exposure is not.

    Post summary

    The article documents the active exploitation of Langflow CVE‑2026‑55255 with a federal remediation deadline, calls for immediate patching to v1.9.2, and emphasizes credential harvesting via an IDOR.

    10010154
    36 followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    Attackers using Langflow flaw for credential harvesting (CVE-2026-55255) https://www.helpnetsecurity.com/2026/07/08/langflow-vulnerability-cve-2026-55255-exploited/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    Report confirms that attackers are actively exploiting CVE-2026-55255 in Langflow for credential harvesting, but offers no technical details, PoC, or mitigation information.

    010011.1K
    195.0K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    Three critical Langflow security vulnerabilities (CVE-2026-55255, CVE-2026-55447, CVE-2026-55450) expose AI applications to RCE and DoS attacks. Patch now. #Langflow #Vulnerability #CyberSecurity #CVE #AppSec https://securityonline.info/langflow-security-vulnerabilities https://t.co/9eNzB5fdOy

    Post summary

    The tweet informs that three critical Langflow CVEs can lead to RCE and DoS attacks and urges users to apply the available patch immediately.

    00020474
    12.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more