CVE-2026-55255 CRITICAL

Langflow Langflow Vulnerability
Generated: 10 Oct 2026 19:56 • CVE Threat Intelligence

Description

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.

9.8
CVSS CRITICAL

Details

Published
07 Jul 2026 00:00
Modified
N/A
Source
CIRCL
Vendor
Langflow
Product
Langflow
Fix Version
Vendor Patch / Mitigation Available