CVE Tools

CVE-2025-34291

Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE

Published: Dec 5, 2025Updated: Jul 14, 2026 Sources: CVE List NVD GHSACWE-346

Description

Langflow CORS misconfiguration enables Account Takeover and RCE

In plain language

AI Act now

Langflow versions up to 1.6.9 have a web misconfiguration that can let an attacker steal users’ login tokens and take over accounts, with the ability to run code on your server—most small businesses using Langflow should treat this as urgent and update to 1.7.0.

Executive summary

CVE-2025-34291 is a CORS misconfiguration in Langflow (<= 1.6.9) that enables token hijacking and remote code execution by letting an attacker abuse browser cross-origin requests to capture authentication tokens and then trigger attacker-controlled actions on the target system.

If affected, business impact
Full account takeoverRemote code execution on serverService disruptionTheft of access to AI workflows

What to do now

  1. Check your installed Langflow version and confirm whether it is 1.6.9 or older.
  2. Upgrade Langflow to 1.7.0 (or newer) as soon as possible.
  3. If you cannot upgrade immediately, follow the vendor/workaround guidance you receive and temporarily restrict access so the vulnerable service is not reachable from untrusted networks.
  4. After upgrading, verify the service is responding as expected and review authentication-related logs for unusual token or session activity.
pip install -U langflow>=1.7.0
Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:LUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

PyPI
package-ecosystem
Langflow
commercialaka langflow-base, langflow desktop
and 1 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:May 21, 2026
Remediation due:Jun 4, 2026

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

1 exploit source identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available
Workaround Available

References

and 8 more references View all →
3

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2025-34291 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows