CVE-2025-34291
Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
Description
Langflow CORS misconfiguration enables Account Takeover and RCE
In plain language
AI Act nowLangflow versions up to 1.6.9 have a web misconfiguration that can let an attacker steal users’ login tokens and take over accounts, with the ability to run code on your server—most small businesses using Langflow should treat this as urgent and update to 1.7.0.
CVE-2025-34291 is a CORS misconfiguration in Langflow (<= 1.6.9) that enables token hijacking and remote code execution by letting an attacker abuse browser cross-origin requests to capture authentication tokens and then trigger attacker-controlled actions on the target system.
What to do now
- Check your installed Langflow version and confirm whether it is 1.6.9 or older.
- Upgrade Langflow to 1.7.0 (or newer) as soon as possible.
- If you cannot upgrade immediately, follow the vendor/workaround guidance you receive and temporarily restrict access so the vulnerable service is not reachable from untrusted networks.
- After upgrading, verify the service is responding as expected and review authentication-related logs for unusual token or session activity.
pip install -U langflow>=1.7.0CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEVen·The Hacker News· Exploited Adobe ColdFusion web-app
- Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizationsen·The Hacker News· Incident Cavern Manticore nation-state
- Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCEen·The Hacker News· Exploited Langflow MuddyWater (mentioned as exploiting a different Langflow vuln)
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-34291 and every CVE in our database. Create a free account — no credit card required.
Create Free Account