High
Actively Exploited
cisa_kev
·
CVE-2026-55255
Langflow Authorization Bypass Through User-Controlled Key Vulnerability
Published Jul 7, 2026
CVSS 9.9
Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
Affected AI Products
langflow