CVE-2026-55423 Details
Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in. This vulnerability is fixed in 1.7.0.
A session management vulnerability has been identified in Langflow versions prior to 1.7.0. The issue arises because the logout button does not effectively clear the user's session. As a result, the previous user remains logged in unless another user explicitly logs in. This vulnerability can lead to confusion, particularly for users on shared computers, who may mistakenly believe they have successfully logged out.
This vulnerability has been fixed in Langflow version 1.7.0. Users should upgrade to version 1.7.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/langflow-ai/langflow/pull/10527 | [email protected] | Issue TrackingPatch |
| https://github.com/langflow-ai/langflow/pull/10528 | [email protected] | Issue TrackingExploit |
| https://github.com/langflow-ai/langflow/security/advisories/GHSA-7hw8-6q6r-4276 | [email protected] | Vendor AdvisoryExploitPatch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| langflow langflow | < 1.7.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | Initial Analysis | [email protected] |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | [email protected] |