CVE-2025-34291 is a critical chained vulnerability affecting Langflow versions up to and including 1.6.9, enabling account takeover and remote code execution. It stems from an overly permissive CORS configuration combined with a vulnerable refresh token cookie, allowing attackers to steal authentication tokens. With a CVSS score of 8.8 (HIGH), this vulnerability has a low attack complexity and can lead to full system compromise, including arbitrary code execution. While not yet in the KEV catalog or actively exploited, a Nuclei template exists, and it has garnered significant community discussion, indicating potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6.9CPE matchmatch criteria | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* | ||
>= 0, <= 1.6.9CPE match | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.