Understanding Langflow CVE-2026-55255, and why higher CVSS vulnerabilities aren't always the most exploited
Reported 26 Jun 2026 by otx · Severity: medium
On June 25, 2026, the first active exploitation of CVE-2026-55255, a critical CVSS 9.9 Langflow vulnerability, was documented. Langflow is an open-source framework for building AI agents and RAG pipelines. A single operator exploited both CVE-2026-55255 (cross-tenant IDOR) and CV