ACVEAgent configuration vulnerability registry

ACVE-2026-0555

Any authenticated user can run another user's flow on Langflow servers below 1.9.1 by passing the flow's UUID as the model on POST /api/v1/responses; exploited in the wild and in KEV.

Exposure

Reproducibility: partial (trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

ClaimStatusSourceChecked
Identifier CVE-2026-55255Confirmedcveawg.mitre.org2026-09-25
Identifier GHSA-qrpv-q767-xqq2Confirmedapi.osv.dev2026-09-25
Upgrade target 1.9.1Confirmedapi.osv.dev2026-09-25
Latest affected version 1.9.0 (below fixed 1.9.1) is still installable from PyPIConfirmedpypi.org2026-09-25
Severity HIGH (CVSS 8.4); matches CNAConfirmedcveawg.mitre.org2026-09-25

In the wild

exploited-itw · kev, research

Description

What

POST /api/v1/responses takes a flow UUID in its model field, and get_flow_by_id_or_endpoint_name looked a flow up by UUID without checking user_id, so any authenticated user could run any other user's flow, reach data it processes and consume its owner's resources. Langflow's repository advisory scores it 9.9 (AC:L); the CVE record and GitHub's reviewed advisory score it 8.4 (AC:H), which this record follows. Sysdig reported the first known exploitation, seen on 2026-06-25, and CISA added the CVE to KEV on 2026-07-07. What that attacker told the hijacked flows to do is ACVE-2026-0556.

Detection

acve lock does not inventory Python dependencies or Langflow deployments, so this record has no matcher: check pip show langflow and the server image tag by hand.

Fix

Upgrade to 1.9.1.

Fix

Upgrade Langflow to 1.9.1 or later.

  • Upgrade pypi:langflow to 1.9.1. First release with the fix (GHSA-qrpv-q767-xqq2, PR #12832). Owner: operator

References

ADVISORY

FIX

REPORT

WEB

Report a problemJSON