BREAKING
CISA Adds Langflow Flaw to KEV
0
CVSS v3.1
0days
to deadline
0+
GitHub stars
How the IDOR Bypass Works
1Login as user
2Enumerate flow IDs
3Call /responses
4Run others' flows
Patch or Discontinue Use
RemediateBy Jul 10
Update to 1.9.1+
Block external exposure
Review auth settings
If not fixedBOD 26-04
Discontinue product use
Applies to FCEB agencies
Chained With RCE in the Wild
Update Langflow to 1.9.1 Now
AI NEWS BLITZ
CISA has added a critical Langflow authorization bypass flaw to its Known Exploited Vulnerabilities list.