/00 — boot sequence

Hello.

Article

Langflow CVE-2026-55255: CISA Warns of Active Exploitation

July 9, 2026•6 min read
security langflow cve-2026-55255 ai-security cisa vulnerability

For the first time ever, CISA has added an AI agent platform to its Known Exploited Vulnerabilities (KEV) catalog. Langflow, the popular open-source visual framework for building AI agents and RAG pipelines, is under active attack. A critical authorization bypass vulnerability, tracked as CVE-2026-55255 (CVSS 9.9), lets authenticated attackers access and execute flows belonging to any other user , including flows that hold sensitive LLM provider API keys, database credentials, and AWS keys.

Federal agencies must patch by July 10, 2026. If you run Langflow in any environment, here is everything you need to know.

Vulnerability Details

CVE-2026-55255 is a cross-tenant Insecure Direct Object Reference (IDOR) vulnerability in Langflow's /api/v1/responses endpoint. The flaw lets an authenticated attacker access another user's flows simply by changing the flow_id UUID in their request.

  • CVE ID: CVE-2026-55255
  • CVSS Score: 9.9 (Critical)
  • Vulnerability Type: Cross-tenant Insecure Direct Object Reference (IDOR)
  • Affected Endpoint: /api/v1/responses
  • Attack Vector: Authenticated attacker modifies flow_id parameter to access another tenant's flows
  • Fixed In: Langflow version 1.9.1
  • Discovered By: Sysdig Threat Research Team (TRT)

Because Langflow is a multi-tenant platform where different users, teams, or even organizations host their AI agent pipelines on the same server instance, this IDOR allows an attacker to silently traverse between tenants. The API endpoint authenticates the request but never verifies that the requesting user owns the target flow.

Impact Assessment

This is not just a data leak. The impact of CVE-2026-55255 cascades across three critical dimensions:

1. Credential Theft. Langflow flows commonly integrate with external AI services. A single flow can contain embedded LLM provider API keys (OpenAI, Anthropic, Together AI, HuggingFace), database connection strings, and cloud service credentials. Sysdig observed attackers using the IDOR to specifically target and extract LLM provider keys and AWS keys from other tenants' flows.

2. Compute Hijacking. Once attackers accessed other users' flows, they chained CVE-2026-55255 with CVE-2026-33017 (a critical Langflow RCE patched in March 2026) to deploy second-stage implants. The observed campaign deployed botnet payloads and cryptomining software, turning compromised Langflow servers into revenue-generating assets for the attackers.

3. Supply Chain Risk. AI agent flows run on these servers. An attacker who accesses and modifies another user's flow can inject malicious behavior into AI agent pipelines , altering prompts, redirecting API calls, or poisoning RAG data sources.

Affected Systems

  • All Langflow versions prior to 1.9.1 are vulnerable
  • Internet-exposed Langflow instances are at highest risk
  • Multi-tenant Langflow deployments (where multiple teams share one instance) face the broadest blast radius
  • Air-gapped/internal instances are not immune if any authenticated user account is compromised

Sysdig's telemetry shows that the attacker specifically targeted internet-exposed Langflow instances, scanning for the application's default API endpoints. The campaign was opportunistic, targeting any reachable instance.

Mitigation and Patching

Immediate action required. Follow these steps in order:

1. Upgrade to Langflow 1.9.1

The fix is included in Langflow 1.9.1. Upgrade immediately:

bash

2. Rotate All Exposed Credentials

Assume that any API keys, database passwords, or cloud credentials stored in Langflow flows prior to patching have been compromised. Rotate them immediately:

  • LLM provider API keys (OpenAI, Anthropic, etc.)
  • AWS access keys and secrets
  • Database connection strings
  • Any other secrets referenced in flows

3. Audit for Compromise

Check your Langflow server for signs of intrusion:

  • Unexpected flows or flow modifications
  • Unknown user accounts
  • Unusual API calls to /api/v1/responses with varying flow_id values
  • Suspicious outbound network connections (cryptomining pools, C2 infrastructure)
  • Unexplained files in the Langflow data directory

4. Restrict Network Exposure

If your Langflow instance does not need to be internet-facing, place it behind a VPN or firewall. For instances that must be exposed:

  • Implement additional WAF rules to detect IDOR-style parameter manipulation
  • Enable comprehensive API audit logging
  • Consider a reverse proxy with rate limiting

Detection

Sysdig's report provides actionable indicators:

  • Attacker IP: 45.207.216[.]55 , observed probing Langflow instances and executing the attack chain between June 22-25, 2026
  • Attack Pattern: Application/auth reconnaissance → flow enumeration → IDOR exploitation → RCE chaining → implant deployment
  • Behavioral Signal: Repeated requests to /api/v1/responses with systematically varying flow_id parameters

Look for HTTP requests where an authenticated user accesses an unusually large number of flow IDs in a short period. This bulk enumeration is a strong signal of IDOR exploitation.

Broader Context: Langflow's Growing Security Problem

CVE-2026-55255 is the latest in a troubling pattern. Langflow has been a repeated target over the past year:

CVETypeSeverityStatus
CVE-2025-3248Missing AuthenticationCriticalUsed by JadePuffer ransomware
CVE-2026-0770Authentication BypassHighPatched
CVE-2026-33017Unauthenticated RCECriticalPatched March 2026
CVE-2026-5027Path TraversalHighActively exploited
CVE-2026-21445Code InjectionHighPatched
CVE-2026-55255Cross-tenant IDOR9.9 CriticalCISA KEV , patch now

AI agent platforms are a high-value target because they concentrate exactly what attackers want: compute resources, API credentials, and access to AI pipelines. As Langflow and similar tools become central to enterprise AI workflows, their security posture directly impacts organizational risk.

Frequently Asked Questions

Q: Does CVE-2026-55255 require authentication to exploit? A: Yes, the attacker must be an authenticated user on the Langflow instance. However, chaining with other Langflow CVEs (specifically the unauthenticated RCE CVE-2026-33017) allows attackers to gain initial access and then pivot to the IDOR.

Q: Is my Langflow instance compromised if I am fully patched? A: If you are running Langflow 1.9.1 or later, you are protected against CVE-2026-55255. However, review the detection guidance above and rotate credentials as a precaution.

Q: Do I need to be exposed to the internet to be at risk? A: Direct internet exposure dramatically increases risk, but any instance where an attacker can obtain authenticated access , via credential stuffing, session hijacking, or chained CVEs , is vulnerable.

Q: How does this affect my LLM API keys? A: If a compromised flow contained API keys, those keys should be considered stolen. Attackers can use them to make unauthorized API calls at your expense. Rotate all keys stored in Langflow immediately.

Key Takeaways

  • CVE-2026-55255 is a critical (CVSS 9.9) cross-tenant IDOR in Langflow that lets attackers access any user's flows
  • Active exploitation observed since June 25, 2026, with attackers chaining it with an RCE for full server compromise
  • CISA added Langflow to KEV for the first time , a historic move signaling that AI agent platforms are now squarely in the crosshairs
  • Patch to Langflow 1.9.1 immediately and rotate all credentials that may have been exposed
  • AI agent platforms are prime targets , they concentrate credentials, compute, and pipeline access in one place

Conclusion

CVE-2026-55255 marks a turning point. The first CISA KEV entry for an AI agent platform signals that attackers are systematically targeting the infrastructure behind the AI boom. If you run Langflow , or any AI agent orchestration platform , treat this as a wake-up call. Patch aggressively, audit your credentials, and assume that your AI infrastructure is a high-value target.

The tools we use to build AI agents are themselves becoming attack surfaces. Securing them is no longer optional.


Sources: CISA KEV Catalog, Sysdig Threat Research, The Hacker News, BleepingComputer, SecurityWeek

Automated Transmission

This entry was synthesized and populated dynamically using native API integrations.

Resources & Links