HackerFeeds
All CVEs

CVE-2025-34291

HIGH8.8
CISA KEV

Published 2025-12-05 · Updated 2026-07-14 · Source disclosure@vulncheck.com

Description

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CWE-346

CISA Known-Exploited Vulnerability

Product: LangflowLangflow

Name: Langflow Origin Validation Error Vulnerability

Date added: 2026-05-21 · Due: 2026-06-04

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

View on NVD