CVE Tools

Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)

Help Net SecurityBy Zeljka Zorz

Reported exploitedLangflow

Our summary

Attackers are exploiting a recently cataloged vulnerability in Langflow (CVE-2026-55255), an open-source AI workflow framework, to harvest credentials and sensitive data. CISA added this insecure direct object reference (IDOR) flaw to its Known Exploited Vulnerabilities list on July 7, following active exploitation observed by the Sysdig Threat Research Team. The flaw enables authenticated attackers to execute another user’s flow using just the flow ID, potentially leading to cross-tenant data exposure and secret theft. Federal agencies have until July 10 to apply the fix, as mitigation is critical due to ongoing attacks.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store