CVE 9.4 CRITICAL

Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE_CVE-2025-34291

9.4 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.

AI Analysis

Langflow is vulnerable to a chained vulnerability that enables account takeover and remote code execution due to an overly permissive CORS configuration and a refresh token cookie configured as SameSite=None.

Basic Information

ID CVE-2025-34291
Source VulnCheck
Published Dec 5, 2025 at 22:27

Affected Product

Vendor Langflow
Product Langflow
Affected Versions Langflow Langflow 0

CWE Classification

AI Assessment

AI Score 9.4 / 10
AI Severity Critical
Vendor Langflow
Product Langflow
Version 1.6.9

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.