


Perceptive Security
SOC/SIEM Consultancy

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to anot…
Published:
7 juli 2026 om 00:00:00
Alert date:
7 juli 2026 om 18:06:03
Source:
cisa.gov

Web Technologies, Identity & Access, Emerging Technologies
CVE-2026-55255 is an authorization bypass through user-controlled key vulnerability affecting Langflow, an AI workflow builder. An authenticated attacker can execute any flow belonging to another user by specifying the victim's flow ID in the request, effectively bypassing authorization controls. This vulnerability allows lateral movement between user accounts within the same Langflow instance. The issue is tracked under GHSA-qrpv-q767-xqq2 on GitHub Security Advisories. CISA has included this vulnerability under BOD 26-04, which prioritizes security updates based on risk. Organizations running Langflow are advised to apply patches immediately and review forensic triage requirements as outlined in the BOD 26-04 implementation guidance. The vulnerability is rated high criticality due to its potential for unauthorized access to sensitive AI workflows and data.
Technical details
Mitigation steps:
Affected products:
Langflow
Related links:
https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2
https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
https://nvd.nist.gov/vuln/detail/CVE-2026-55255
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.