{"id":"CVE-2025-34291","title":"Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution","summary":"Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a …","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-346"],"vendor":"langflow","product":"langflow","affected":["langflow <= 1.6.9"],"published":"2025-12-05","updated":"2026-07-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-34291","references":[{"url":"https://github.com/langflow-ai/langflow","label":"disclosure@vulncheck.com"},{"url":"https://www.obsidiansecurity.com/blog/cve-2025-34291-critical-account-takeover-and-rce-vulnerability-in-the-langflow-ai-agent-workflow-platform","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/langflow-cors-misconfiguration-to-token-hijack-and-rce","label":"disclosure@vulncheck.com"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34291","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.crowdsec.net/vulntracking-report/cve-2025-34291","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.83629,"epssPercentile":0.99682,"kev":true,"kevDateAdded":"2026-05-21","kevDueDate":"2026-06-04","kevRansomware":false,"exploited":true,"ingestedAt":"2026-07-15T13:44:03.544Z","exploits":{"github":2,"githubRepos":["https://github.com/amnnrth/CVE-2025-34291_cors_security_scanner","https://github.com/ridhinva/langflow-cors-scanner"],"nuclei":["CVE-2025-34291"],"checkedAt":"2026-09-21T15:27:21.814Z"},"exploitAvailable":true,"slug":"CVE-2025-34291","body":"## Overview\n\nLangflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.\n\n## Affected\n\n- `langflow <= 1.6.9`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":90,"depthScoreParts":{"impact":48.4,"likelihood":16.7,"exploitation":25,"ransomware":0},"changes":[{"seq":4818,"id":"CVE-2025-34291","ts":1788887208411,"field":"exploit_available","old":"false","new":"true"},{"seq":3701,"id":"CVE-2025-34291","ts":1788886325518,"field":"exploit_available","old":"true","new":"false"},{"seq":2546,"id":"CVE-2025-34291","ts":1788883007078,"field":"exploit_available","old":"false","new":"true"},{"seq":1575,"id":"CVE-2025-34291","ts":1788882407336,"field":"exploit_available","old":"true","new":"false"},{"seq":689,"id":"CVE-2025-34291","ts":1788881844054,"field":"exploit_available","old":"false","new":"true"}]}