CVE-2026-55255
HIGH(8.4)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
- CVSS 8.4 — Hoch
- Im CISA KEV-Katalog (aktiv ausgenutzt)
Erwähnungen (letzte 60 Tage)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
0.9%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
8.4
Technische Schwere
SecBoard-Einordnung
CVE-2026-55255 betrifft Langflow, ein Tool zum Erstellen und Bereitstellen von KI-Agenten und Workflows. Es handelt sich um eine Insecure Direct Object Reference (IDOR)-Schwachstelle im /api/v1/responses-Endpunkt. Ein authentifizierter Angreifer kann dadurch Flows anderer Benutzer ausführen, indem er deren Flow-ID in der Anfrage angibt.
Die Schwachstelle wird mit einem CVSS-Score von 8.4 (HIGH) bewertet und hat eine EPSS-Wahrscheinlichkeit von 29%. Besonders kritisch ist, dass sie in der CISA KEV-Liste aufgeführt ist, was bedeutet, dass sie aktiv ausgenutzt wird. Dies erhöht die Dringlichkeit der Behebung erheblich.
Security-Teams sollten umgehend prüfen, ob sie betroffene Langflow-Instanzen einsetzen. Eine sofortige Aktualisierung auf Version 1.9.1 oder höher ist dringend erforderlich, um das Risiko einer Ausnutzung zu minimieren und die Integrität der Benutzer-Flows zu schützen.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.
GitHub Advisories
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
In diesen Analysen erwähnt
Referenzen
- https://github.com/langflow-ai/langflow/commit/2c9f498d664a3c32698b57d7c5e752625...
- https://github.com/langflow-ai/langflow/pull/12832
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2
- https://webflow.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-hi...
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-...