CISA orders feds to prioritize patching Langflow auth bypass flaw
AI Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to urgently patch CVE-2026-55255, an authentication bypass vulnerability in the Langflow AI development platform. This flaw allows authenticated attackers to access other users' workflows by manipulating the /api/v1/responses endpoint with a victim's flow_id, enabling data theft and resource abuse. Exploitation in the wild has been observed since June 25, with attackers pursuing financial gain through compute resource hijacking and credential theft. CISA has also added related Langflow vulnerabilities to its Known Exploited Vulnerabilities catalog, including CVE-2025-3248 and CVE-2026-33017, exploited by ransomware actors.
AI-extracted · verify before operational use