9.4
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.
AI Analysis
Langflow is vulnerable to a chained vulnerability that enables account takeover and remote code execution due to an overly permissive CORS configuration and a refresh token cookie configured as SameSite=None.
Basic Information
ID
CVE-2025-34291
Source
VulnCheck
Published
Dec 5, 2025 at 22:27
Affected Product
Vendor
Langflow
Product
Langflow
Affected Versions
Langflow Langflow 0
CWE Classification
AI Assessment
AI Score
9.4 / 10
AI Severity
Critical
Vendor
Langflow
Product
Langflow
Version
1.6.9