CVE-2025-34291 Scanner
CVE-2025-34291 Scanner - CORS Misconfiguration vulnerability in Langflow AI
Used 2.4k times · 5.9k assets checked · domain, subdomain, ipv4
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.
CVE-2025-34291 Scanner - CORS Misconfiguration vulnerability in Langflow AI
Used 2.4k times · 5.9k assets checked · domain, subdomain, ipv4
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →