Skip to content
LangflowGHSA-577h-p2hh-v4mv

Langflow CORS misconfiguration enables Account Takeover and RCE

Critical8.8CVE-2025-34291 · Published Dec 6, 2025 · updated May 29, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
langflow
PyPI
< 1.7.01.7.0
Details and references

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints , including built-in code-execution functionality , allowing the attacker to execute arbitrary code and achieve full system compromise.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-346
Also known as
CVE-2025-34291, PYSEC-2025-78

More Langflow advisories

All Langflow
DateAdvisory
Dec 192025Langflow vulnerable to Server-Side Request Forgery
CVE-2025-68477High7.7fixed in 1.7.1
Dec 192025External Control of File Name or Path in Langflow
CVE-2025-68478High7.1fixed in 1.7.1
Jan 2Langflow Missing Authentication on Critical API Endpoints
CVE-2026-21445Highfixed in 1.7.1
Jan 23Langflow affected by Remote Code Execution via validate_code() exec()
CVE-2026-0770Highno fix yet
Feb 27Langflow has Remote Code Execution in CSV Agent
CVE-2026-27966Critical9.8no fix yet
Mar 17Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
CVE-2026-33017Critical9.8fixed in 1.9.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.