CISA Orders Feds to Patch Langflow Flaw
CISA told federal agencies to patch a Langflow auth bypass by Friday. Attackers are already inside.
The flaw lets authenticated attackers execute flows belonging to other Langflow users by supplying a victim’s flow ID. CVSS 9.9, actively exploited.
Affects Langflow versions before 1.9.1. Federal networks, research labs, and anyone running the open-source framework need to move.
CISA added the bug to its Known Exploited Vulnerabilities list hours before the directive.
