9.4
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H
Description
CVE-2025-34291 — Langflow Origin Validation / CORS Overview Overly permissive CORS config combined with refresh token cookie config allows credential theft. | Field | Value | |-------|-------| | CVE | CVE-2025-34291 | | Severity | HIGH | | Product |...
Basic Information
ID
5AB85FC2-7A7B-5CF1-ABF2-AC44C5026986
Published
May 22, 2026 at 20:44