Critical CORS misconfiguration in Langflow AI framework allows account takeover and remote code execution through cross-origin token hijacking. Affects internet-facing Langflow deployments up to version 1.6.9, with active exploitation observed in the wild.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: USER_INTERACTION
CVE Published: 2025-12-05
Added to CISA KEV: 2026-05-21 167 DAYS BETWEEN CVE AND KEV
Active exploitation of CVE-2025-34291 was observed starting on January 23rd, 2026. The vulnerability has not yet been added to CISA KEV, but we expect this to happen soon. CVE-2025-34291 originates from an issue in the cross-site request forgery protection of the LangFlow default configuration. As aโฆ