CVE-2025-34291 — Langflow Origin Validation Error Vulnerability
Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obt
- Severity
- critical
- Product
- Langflow Langflow
- Published
- 2026-05-21
- EPSS
- 0.836
- CISA KEV
- Known exploited
- Ransomware
- Known campaign use
References and validation
- https://github.com/search?q=CVE-2025-34291&type=repositories
- https://nvd.nist.gov/vuln/detail/CVE-2025-34291
Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.