← Vulnerability feed

Vulnerability record · CVE-2025-34291 · published 5 December 2025

CVE-2025-34291: Langflow CORS misconfiguration leads to token theft and RCE

Langflow · Langflow

Langflow up to and including 1.6.9 ships an overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) and a refresh token cookie set to SameSite=None. A malicious webpage can make credentialed cross-origin requests to the refresh endpoint and obtain fresh access/refresh token pairs for a victim session. The stolen tokens unlock authenticated endpoints, including built-in code execution, leading to full system compromise.

9.4 CVSS 4.0 Critical CISA KEV since 21 May 2026 EPSS 93% · top 0.2% CWE-346 · Origin validation error
9.4CVSS 4.0 base score
93%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 1 tagged exploit
14 Jul 2026Last modified by NVD

Description

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 4.0 base score 9.4, CISA KEV listing with a 2026-06-04 remediation due date, and a 99.7th percentile EPSS probability make this an actively exploited, remotely reachable path to full compromise.

What it is

Langflow up to and including 1.6.9 ships an overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) and a refresh token cookie set to SameSite=None. A malicious webpage can make credentialed cross-origin requests to the refresh endpoint and obtain fresh access/refresh token pairs for a victim session. The stolen tokens unlock authenticated endpoints, including built-in code execution, leading to full system compromise.

Impact

An attacker who lures a logged-in victim to a malicious page gains that user's tokens, takes over the account, and can execute arbitrary code on the Langflow host, resulting in full system compromise.

Attack surface

Reachable over the network through a victim's browser: the attacker needs the victim to visit a malicious webpage (UI:P) while authenticated, and no prior authentication is required by the attacker (PR:N). The flaw is in origin validation on the refresh endpoint, not in an authenticated API path.

Exploitation

CVE-2025-34291 is listed in CISA KEV (added 2026-05-21) and has an EPSS 30-day probability of 0.836 (99.7th percentile), and a reference is tagged Exploit, indicating active exploitation. No ransomware campaign use is documented.

What to do

  • Upgrade Langflow past 1.6.9 to a fixed release as soon as the vendor provides one; treat 1.6.9 and earlier as vulnerable.
  • If patching is not immediately possible, restrict CORS to explicit trusted origins and stop sending credentials with wildcard origins, and set the refresh token cookie to SameSite=Strict or Lax.
  • Isolate Langflow instances from untrusted networks and do not expose the UI or API directly to the internet.
  • Rotate all Langflow session tokens, refresh tokens and any credentials or secrets reachable from the instance, since token theft may already have occurred.
  • Follow CISA KEV required action and BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.

Detection

  • Monitor Langflow access logs for refresh endpoint requests with unexpected or attacker-controlled Origin headers, especially cross-origin requests carrying cookies.
  • Alert on token refresh or authenticated API calls from IP addresses or user agents that differ from the victim's normal session.
  • Hunt for use of Langflow code-execution endpoints shortly after a token refresh, particularly from new source IPs.
  • Review outbound connections and process execution on Langflow hosts for signs of post-exploitation activity following suspicious token use.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-34291 to the Known Exploited Vulnerabilities catalog on 21 May 2026 as "Langflow Origin Validation Error Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 4 June 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-34291 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-9198Langflow auto_login and code validation chain enables unauthenticated RCEIBM Langflow OSS 1.0.0 through 1.10.0 exposes /api/v1/auto_login, which mints SUPERUSER tokens to any network caller, and /api/v1/validate/code, whic…KEVEPSS 29%analysed9.8CVE-2026-0770Langflow validate endpoint exec_globals remote code executionLangflow mishandles the exec_globals parameter passed to its validate endpoint, allowing functionality from an untrusted control sphere to be include…KEVEPSS 64%analysed9.8CVE-2025-3248Langflow unauthenticated code injection in validate/code endpointLangflow versions prior to 1.3.0 expose the /api/v1/validate/code endpoint without authentication, allowing code injection. A remote attacker can sen…KEVEPSS 100%analysed9.3CVE-2026-33017Langflow build_public_tmp endpoint unauthenticated remote code executionLangflow versions prior to 1.9.0 expose the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint without authentication, and when the optional data …KEVEPSS 25%analysed8.4CVE-2026-55255Langflow IDOR in responses endpoint allows cross-user flow executionLangflow before 1.9.1 has an insecure direct object reference in the /api/v1/responses endpoint. An authenticated attacker can supply another user's …KEVEPSS 0.89%analysed10.0CVE-2026-10134Langflow code injection vulnerabilityIBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversat…EPSS 0.64%10.0CVE-2026-10561Langflow code injection vulnerabilityIBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass tha…EPSS 1.0%9.9CVE-2026-19295Langflow vulnerabilityIBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving…EPSS 3.3%

Source: NIST National Vulnerability Database (record CVE-2025-34291), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.