PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Misconfiguration·Updated Jan 3, 2026

Langflow AI <= 1.6.9 - CORS Misconfiguration

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
2.9k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2025-34291
9.4
CVSScritical
Exploitable remotely over the internet · no authentication required.

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.

Attack Vector
Network
Privileges Req.
None
User Interaction
P
Affected
Langflowby Langflow
0
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Langflow AI <= 1.6.9 - CORS Misconfiguration CVE-2025-34291 Scanner | S4E