CVE-2025-34291
Langflow Origin Validation Error Vulnerability
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog: attackers are using it. If you run Langflow, fix it now.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
US federal civilian agencies must remediate by Jun 4, 2026.
Patch status
No official fix confirmed yet
Until a fix ships, follow the vendor's mitigations and CISA's required action, limit exposure of affected systems, and watch this record for a patch.
Description
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
Affected products
| Product | Vendor | Affected versions | Source |
|---|---|---|---|
| Langflow | Langflow | <= 1.6.9 | KEV |
Sources: KEV = CISA Known Exploited Vulnerabilities catalog.
Intelligence timeline
Developments from the last 30 days, newest first.
No developments recorded for CVE-2025-34291 in the last 30 days.
1 earlier event is available with a subscription. See plans.
Coverage
We have not published a story about this vulnerability yet.
