CVE-2026-55255: Langflow Authorization Bypass Through User-Controlled Key
Langflow Authorization Bypass Through User-Controlled Key Vulnerability. Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
- CISA KEV-listed (remediation due 2026-07-10)
- EPSS 29.1% (98.0% percentile)
- CVSS 8.4 high