CVE-2026-55423Disclosure(langflow / langflow)

LOWCVSS 6.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch langflow langflow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in. This vulnerability is fixed in 1.7.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-23: 2Patch / Workaround · 2026-06-23: 1Technical Details · 2026-06-23: 206-23
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-55423 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays l… https://www.cve.org/CVERecord?id=CVE-2026-55423 ----- Traducción: CVE-2026-55423 Lan… http://infoflow.cloud`

    Post summary

    CVE-2026-55423 is a session‑management flaw in Langflow where logout fails to clear the session; upgrading to version 1.7.0 fixes the issue. No PoC, exploit, or active exploitation is mentioned.

    0101134
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-55423 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays l… https://www.cve.org/CVERecord?id=CVE-2026-55423

    Post summary

    The CVE describes a session fixation flaw in Langflow’s logout functionality that was fixed in version 1.7.0.

    00000717
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more