Vulnerability  ·  2026-05-22

Langflow AI Workflow Platform Origin Validation Error Enables Cross-Origin Token Theft — CVE-2025-34291 Added to CISA KEV

VulnerabilityHigh impactGlobalCVE-2025-34291
Langflow, an AI agent and workflow platform used to build language-model-driven applications, contains an origin validation error vulnerability stemming from overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None. A malicious webpage can perform cross-origin requests that include credentials and successfully call the refresh endpoint, enabling authenticated access and potential paths to remote code execution.
An attacker hosts a malicious page and tricks a victim with an active Langflow session into visiting it. The page sends cross-origin requests to the Langflow instance; due to the permissive CORS policy and cookie configuration, the victim's browser attaches credentials. The attacker can then obtain tokens, hijack the session, and potentially execute code through Langflow's workflow orchestration capabilities.
Langflow versions prior to 1.9.3. Organizations using Langflow for AI agent development, workflow automation, or LLM orchestration are affected.
Upgrade to Langflow 1.9.3 or later. Apply mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. Federal civilian agencies must apply mitigations by June 4, 2026, per CISA KEV requirement.
Sources
CISA KEV CatalogLangflow GitHub ReleaseNVD CVE-2025-34291
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →