top of page
perceptive_background_267k.jpg

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to anot…

Published:

7 juli 2026 om 00:00:00

Alert date:

7 juli 2026 om 18:06:03

Source:

cisa.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Emerging Technologies

CVE-2026-55255 is an authorization bypass through user-controlled key vulnerability affecting Langflow, an AI workflow builder. An authenticated attacker can execute any flow belonging to another user by specifying the victim's flow ID in the request, effectively bypassing authorization controls. This vulnerability allows lateral movement between user accounts within the same Langflow instance. The issue is tracked under GHSA-qrpv-q767-xqq2 on GitHub Security Advisories. CISA has included this vulnerability under BOD 26-04, which prioritizes security updates based on risk. Organizations running Langflow are advised to apply patches immediately and review forensic triage requirements as outlined in the BOD 26-04 implementation guidance. The vulnerability is rated high criticality due to its potential for unauthorized access to sensitive AI workflows and data.

Technical details

Mitigation steps:

Affected products:

Langflow

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page