Back to articles

Tag archive

#langflow

CVE-2025-34291: Langflow Origin Validation Error Vulnerability
May 22, 2026

CVE-2025-34291: Langflow Origin Validation Error Vulnerability

Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.

May 22, 20262 min read0 reactions0 comments