ACVE-2026-0555
Any authenticated user can run another user's flow on Langflow servers below 1.9.1 by passing the flow's UUID as the model on POST /api/v1/responses; exploited in the wild and in KEV.
Exposure
Reproducibility: partial (trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
| Claim | Status | Source | Checked |
|---|---|---|---|
| Identifier CVE-2026-55255 | Confirmed | cveawg.mitre.org | 2026-09-25 |
| Identifier GHSA-qrpv-q767-xqq2 | Confirmed | api.osv.dev | 2026-09-25 |
| Upgrade target 1.9.1 | Confirmed | api.osv.dev | 2026-09-25 |
| Latest affected version 1.9.0 (below fixed 1.9.1) is still installable from PyPI | Confirmed | pypi.org | 2026-09-25 |
| Severity HIGH (CVSS 8.4); matches CNA | Confirmed | cveawg.mitre.org | 2026-09-25 |
In the wild
Description
What
POST /api/v1/responses takes a flow UUID in its model field, and get_flow_by_id_or_endpoint_name looked a flow up by UUID without checking user_id, so any authenticated user could run any other user's flow, reach data it processes and consume its owner's resources. Langflow's repository advisory scores it 9.9 (AC:L); the CVE record and GitHub's reviewed advisory score it 8.4 (AC:H), which this record follows. Sysdig reported the first known exploitation, seen on 2026-06-25, and CISA added the CVE to KEV on 2026-07-07. What that attacker told the hijacked flows to do is ACVE-2026-0556.
Detection
acve lock does not inventory Python dependencies or Langflow deployments, so this record has no matcher: check pip show langflow and the server image tag by hand.
Fix
Upgrade to 1.9.1.
Fix
Upgrade Langflow to 1.9.1 or later.
- Upgrade
pypi:langflowto1.9.1. First release with the fix (GHSA-qrpv-q767-xqq2, PR #12832). Owner: operator
References
ADVISORY
FIX
- https://github.com/langflow-ai/langflow/pull/12832
- https://github.com/langflow-ai/langflow/commit/2c9f498d664a3c32698b57d7c5e752625291060e
- https://github.com/langflow-ai/langflow/releases/tag/v1.9.1