Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2025-34291
Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N P H H H 9.4 .9281 99.8 YES
AFFECTED
Product Versions Fixed
Langflow unspecified —
TIMELINE
Apr 15 Reserved by VulnCheck
Dec 5 Published (CNA: VulnCheck)
May 21 Added to CISA KEV, remediation due 2026-06-04
Jun 5 DUE DATE PASSED — CVE-2025-34291 (Langflow). CISA remediation deadline was June 4, 2026; still in catalog.
Description
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| April 15, 2025 | Reserved | Reserved by VulnCheck |
| December 5, 2025 | Published | Published (CNA: VulnCheck) |
| May 21, 2026 | KEV ADDED | Added to CISA KEV, remediation due 2026-06-04 |
| June 5, 2026 | DUE DATE PASSED | DUE DATE PASSED — CVE-2025-34291 (Langflow). CISA remediation deadline was June 4, 2026; still in catalog. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Langflow | Langflow | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-34291 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.