Critical Alert 1 Active Exploit Detected Today

CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability →
Powered by CVE Watchtower
×
August 6, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-55255NVD

Vulnerability Summary

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.
Severity Level
HIGH(8.4)
Published Date
Jun 23, 2026
Last Modified
Jul 8, 2026
Exploitation Status
ACTIVE
EPSS Score (30-Day)
29.05%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityLow