Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)
Reported exploitedLangflowOur summary
Attackers are exploiting a recently cataloged vulnerability in Langflow (CVE-2026-55255), an open-source AI workflow framework, to harvest credentials and sensitive data. CISA added this insecure direct object reference (IDOR) flaw to its Known Exploited Vulnerabilities list on July 7, following active exploitation observed by the Sysdig Threat Research Team. The flaw enables authenticated attackers to execute another user’s flow using just the flow ID, potentially leading to cross-tenant data exposure and secret theft. Federal agencies have until July 10 to apply the fix, as mitigation is critical due to ongoing attacks.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.