Langflow Auth Bypass Vulnerability: CVE-2026-55255 Confirmed Exploited
Langflow has a confirmed authorization bypass vulnerability tracked as CVE-2026-55255 that allows authenticated attackers to execute flows belonging to other users. Upgrade to the latest version to mitigate this risk.
What happened
Langflow, a visual framework for building AI agents, contains an authorization bypass vulnerability through a user-controlled key. This allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. The vulnerability affects multiple versions of Langflow, as detailed in the provided data.
CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, indicating active exploitation. Federal agencies have been ordered to prioritize patching this flaw. Sysdig's Threat Research Team first identified this Insecure Direct Object Reference (IDOR) security flaw.
To assess your exposure, check if you are using an affected version of Langflow as listed in the provided data. If so, upgrade to the latest version of Langflow that patches this vulnerability. Additionally, review access controls for user-controlled keys to ensure proper authorization.
How 0Day mitigates this
langflow is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.