PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVE

CVE-2025-34291

9.4
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.

Attack Vector
Network
Privileges Req.
None
User Interaction
P
langflow
Updated Sep 22, 2026View on NVD →
S4E scanner
criticalMisconfiguration~10 seconds

CVE-2025-34291 Scanner

CVE-2025-34291 Scanner - CORS Misconfiguration vulnerability in Langflow AI

Used 2.4k times · 5.9k assets checked · domain, subdomain, ipv4

CVE history: langflow

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →