VulnerabilityAnalyzed
CVE-2026-55423
This vulnerability is fixed in 1.7.0.
MEDIUM 6.1EPSS 0.22%
Does this matter?
Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.
Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in. This vulnerability is fixed in 1.7.0.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.22% probability · 13th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-613
- Affected
- langflow/langflow
- Source
- security-advisories@github.com
References
- https://github.com/langflow-ai/langflow/pull/10527Issue Tracking, Patch
- https://github.com/langflow-ai/langflow/pull/10528Issue Tracking, Exploit
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-7hw8-6q6r-4276Vendor Advisory, Exploit, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.