CVE-2026-55423

MEDIUM

Langflow: Logout button does not clear session

Title source: cna
STIX 2.1

Description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in. This vulnerability is fixed in 1.7.0.

References (3)

Core 3
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/langflow-ai/langflow/pull/10527
X_Refsource_Misc x_refsource_misc
https://github.com/langflow-ai/langflow/pull/10528

Scores

CVSS v3 6.1
EPSS 0.0019
EPSS Percentile 8.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-613
Status published
Products (2)
langflow/langflow < 1.7.0
langflow-ai/langflow < 1.7.0
Published Jun 23, 2026
Tracked Since Jun 23, 2026