Vulnerability record · CVE-2025-34291 · published 5 December 2025
CVE-2025-34291: Langflow CORS misconfiguration leads to token theft and RCE
Langflow · Langflow
Langflow up to and including 1.6.9 ships an overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) and a refresh token cookie set to SameSite=None. A malicious webpage can make credentialed cross-origin requests to the refresh endpoint and obtain fresh access/refresh token pairs for a victim session. The stolen tokens unlock authenticated endpoints, including built-in code execution, leading to full system compromise.
Description
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityCVSS 4.0 base score 9.4, CISA KEV listing with a 2026-06-04 remediation due date, and a 99.7th percentile EPSS probability make this an actively exploited, remotely reachable path to full compromise.
What it is
Langflow up to and including 1.6.9 ships an overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) and a refresh token cookie set to SameSite=None. A malicious webpage can make credentialed cross-origin requests to the refresh endpoint and obtain fresh access/refresh token pairs for a victim session. The stolen tokens unlock authenticated endpoints, including built-in code execution, leading to full system compromise.
Impact
An attacker who lures a logged-in victim to a malicious page gains that user's tokens, takes over the account, and can execute arbitrary code on the Langflow host, resulting in full system compromise.
Attack surface
Reachable over the network through a victim's browser: the attacker needs the victim to visit a malicious webpage (UI:P) while authenticated, and no prior authentication is required by the attacker (PR:N). The flaw is in origin validation on the refresh endpoint, not in an authenticated API path.
Exploitation
CVE-2025-34291 is listed in CISA KEV (added 2026-05-21) and has an EPSS 30-day probability of 0.836 (99.7th percentile), and a reference is tagged Exploit, indicating active exploitation. No ransomware campaign use is documented.
What to do
- Upgrade Langflow past 1.6.9 to a fixed release as soon as the vendor provides one; treat 1.6.9 and earlier as vulnerable.
- If patching is not immediately possible, restrict CORS to explicit trusted origins and stop sending credentials with wildcard origins, and set the refresh token cookie to SameSite=Strict or Lax.
- Isolate Langflow instances from untrusted networks and do not expose the UI or API directly to the internet.
- Rotate all Langflow session tokens, refresh tokens and any credentials or secrets reachable from the instance, since token theft may already have occurred.
- Follow CISA KEV required action and BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.
Detection
- Monitor Langflow access logs for refresh endpoint requests with unexpected or attacker-controlled Origin headers, especially cross-origin requests carrying cookies.
- Alert on token refresh or authenticated API calls from IP addresses or user agents that differ from the victim's normal session.
- Hunt for use of Langflow code-execution endpoints shortly after a token refresh, particularly from new source IPs.
- Review outbound connections and process execution on Langflow hosts for signs of post-exploitation activity following suspicious token use.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-34291 to the Known Exploited Vulnerabilities catalog on 21 May 2026 as "Langflow Origin Validation Error Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 4 June 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/langflow-ai/langflow | Product |
| https://www.obsidiansecurity.com/blog/cve-2025-34291-critical-account-takeover-and-rce-vulnerability-in-the-langflow-ai- | ExploitMitigationThird Party Advisory |
| https://www.vulncheck.com/advisories/langflow-cors-misconfiguration-to-token-hijack-and-rce | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34291 | US Government Resource |
| https://www.crowdsec.net/vulntracking-report/cve-2025-34291 | Third Party Advisory |
Track CVE-2025-34291 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-34291), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.