For the first time ever, CISA has added an AI agent platform to its Known Exploited Vulnerabilities (KEV) catalog. Langflow, the popular open-source visual framework for building AI agents and RAG pipelines, is under active attack. A critical authorization bypass vulnerability, tracked as CVE-2026-55255 (CVSS 9.9), lets authenticated attackers access and execute flows belonging to any other user , including flows that hold sensitive LLM provider API keys, database credentials, and AWS keys.
Federal agencies must patch by July 10, 2026. If you run Langflow in any environment, here is everything you need to know.
Vulnerability Details
CVE-2026-55255 is a cross-tenant Insecure Direct Object Reference (IDOR) vulnerability in Langflow's /api/v1/responses endpoint. The flaw lets an authenticated attacker access another user's flows simply by changing the flow_id UUID in their request.
- CVE ID: CVE-2026-55255
- CVSS Score: 9.9 (Critical)
- Vulnerability Type: Cross-tenant Insecure Direct Object Reference (IDOR)
- Affected Endpoint:
/api/v1/responses - Attack Vector: Authenticated attacker modifies
flow_idparameter to access another tenant's flows - Fixed In: Langflow version 1.9.1
- Discovered By: Sysdig Threat Research Team (TRT)
Because Langflow is a multi-tenant platform where different users, teams, or even organizations host their AI agent pipelines on the same server instance, this IDOR allows an attacker to silently traverse between tenants. The API endpoint authenticates the request but never verifies that the requesting user owns the target flow.
Impact Assessment
This is not just a data leak. The impact of CVE-2026-55255 cascades across three critical dimensions:
1. Credential Theft. Langflow flows commonly integrate with external AI services. A single flow can contain embedded LLM provider API keys (OpenAI, Anthropic, Together AI, HuggingFace), database connection strings, and cloud service credentials. Sysdig observed attackers using the IDOR to specifically target and extract LLM provider keys and AWS keys from other tenants' flows.
2. Compute Hijacking. Once attackers accessed other users' flows, they chained CVE-2026-55255 with CVE-2026-33017 (a critical Langflow RCE patched in March 2026) to deploy second-stage implants. The observed campaign deployed botnet payloads and cryptomining software, turning compromised Langflow servers into revenue-generating assets for the attackers.
3. Supply Chain Risk. AI agent flows run on these servers. An attacker who accesses and modifies another user's flow can inject malicious behavior into AI agent pipelines , altering prompts, redirecting API calls, or poisoning RAG data sources.
Affected Systems
- All Langflow versions prior to 1.9.1 are vulnerable
- Internet-exposed Langflow instances are at highest risk
- Multi-tenant Langflow deployments (where multiple teams share one instance) face the broadest blast radius
- Air-gapped/internal instances are not immune if any authenticated user account is compromised
Sysdig's telemetry shows that the attacker specifically targeted internet-exposed Langflow instances, scanning for the application's default API endpoints. The campaign was opportunistic, targeting any reachable instance.
Mitigation and Patching
Immediate action required. Follow these steps in order:
1. Upgrade to Langflow 1.9.1
The fix is included in Langflow 1.9.1. Upgrade immediately:
2. Rotate All Exposed Credentials
Assume that any API keys, database passwords, or cloud credentials stored in Langflow flows prior to patching have been compromised. Rotate them immediately:
- LLM provider API keys (OpenAI, Anthropic, etc.)
- AWS access keys and secrets
- Database connection strings
- Any other secrets referenced in flows
3. Audit for Compromise
Check your Langflow server for signs of intrusion:
- Unexpected flows or flow modifications
- Unknown user accounts
- Unusual API calls to
/api/v1/responseswith varyingflow_idvalues - Suspicious outbound network connections (cryptomining pools, C2 infrastructure)
- Unexplained files in the Langflow data directory
4. Restrict Network Exposure
If your Langflow instance does not need to be internet-facing, place it behind a VPN or firewall. For instances that must be exposed:
- Implement additional WAF rules to detect IDOR-style parameter manipulation
- Enable comprehensive API audit logging
- Consider a reverse proxy with rate limiting
Detection
Sysdig's report provides actionable indicators:
- Attacker IP:
45.207.216[.]55, observed probing Langflow instances and executing the attack chain between June 22-25, 2026 - Attack Pattern: Application/auth reconnaissance → flow enumeration → IDOR exploitation → RCE chaining → implant deployment
- Behavioral Signal: Repeated requests to
/api/v1/responseswith systematically varyingflow_idparameters
Look for HTTP requests where an authenticated user accesses an unusually large number of flow IDs in a short period. This bulk enumeration is a strong signal of IDOR exploitation.
Broader Context: Langflow's Growing Security Problem
CVE-2026-55255 is the latest in a troubling pattern. Langflow has been a repeated target over the past year:
| CVE | Type | Severity | Status |
|---|---|---|---|
| CVE-2025-3248 | Missing Authentication | Critical | Used by JadePuffer ransomware |
| CVE-2026-0770 | Authentication Bypass | High | Patched |
| CVE-2026-33017 | Unauthenticated RCE | Critical | Patched March 2026 |
| CVE-2026-5027 | Path Traversal | High | Actively exploited |
| CVE-2026-21445 | Code Injection | High | Patched |
| CVE-2026-55255 | Cross-tenant IDOR | 9.9 Critical | CISA KEV , patch now |
AI agent platforms are a high-value target because they concentrate exactly what attackers want: compute resources, API credentials, and access to AI pipelines. As Langflow and similar tools become central to enterprise AI workflows, their security posture directly impacts organizational risk.
Frequently Asked Questions
Q: Does CVE-2026-55255 require authentication to exploit? A: Yes, the attacker must be an authenticated user on the Langflow instance. However, chaining with other Langflow CVEs (specifically the unauthenticated RCE CVE-2026-33017) allows attackers to gain initial access and then pivot to the IDOR.
Q: Is my Langflow instance compromised if I am fully patched? A: If you are running Langflow 1.9.1 or later, you are protected against CVE-2026-55255. However, review the detection guidance above and rotate credentials as a precaution.
Q: Do I need to be exposed to the internet to be at risk? A: Direct internet exposure dramatically increases risk, but any instance where an attacker can obtain authenticated access , via credential stuffing, session hijacking, or chained CVEs , is vulnerable.
Q: How does this affect my LLM API keys? A: If a compromised flow contained API keys, those keys should be considered stolen. Attackers can use them to make unauthorized API calls at your expense. Rotate all keys stored in Langflow immediately.
Key Takeaways
- CVE-2026-55255 is a critical (CVSS 9.9) cross-tenant IDOR in Langflow that lets attackers access any user's flows
- Active exploitation observed since June 25, 2026, with attackers chaining it with an RCE for full server compromise
- CISA added Langflow to KEV for the first time , a historic move signaling that AI agent platforms are now squarely in the crosshairs
- Patch to Langflow 1.9.1 immediately and rotate all credentials that may have been exposed
- AI agent platforms are prime targets , they concentrate credentials, compute, and pipeline access in one place
Conclusion
CVE-2026-55255 marks a turning point. The first CISA KEV entry for an AI agent platform signals that attackers are systematically targeting the infrastructure behind the AI boom. If you run Langflow , or any AI agent orchestration platform , treat this as a wake-up call. Patch aggressively, audit your credentials, and assume that your AI infrastructure is a high-value target.
The tools we use to build AI agents are themselves becoming attack surfaces. Securing them is no longer optional.
Sources: CISA KEV Catalog, Sysdig Threat Research, The Hacker News, BleepingComputer, SecurityWeek
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.