SECURITYHIGHCVE-2025-34291

CVE-2025-34291: Langflow Origin Validation Error

CISA adds CVE-2025-34291 to the Known Exploited Vulnerabilities catalog — an overly permissive CORS configuration combined with a SameSite=None refresh...

Dylan H.

Security Team

May 22, 2026
5 min read
CVE-2025-34291: Langflow Origin Validation Error

Actively exploited

Reported as exploited in the wild (e.g. CISA KEV). Patch or mitigate immediately.

Affected Products

  • Langflow (affected versions per vendor advisory)

Executive Summary

CVE-2025-34291 is an origin validation error vulnerability in Langflow, the popular open-source AI workflow automation platform. The flaw stems from an overly permissive CORS (Cross-Origin Resource Sharing) configuration combined with a refresh token cookie configured as SameSite=None, allowing a malicious webpage to perform cross-origin requests that include user credentials and successfully call the refresh endpoint.

CISA added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on May 21, 2026, confirming active exploitation in the wild. Organizations running Langflow for AI workflow orchestration — particularly those with publicly accessible instances — face elevated risk of session hijacking.


Vulnerability Details

AttributeValue
CVE IDCVE-2025-34291
SeverityHigh
CWECWE-346 — Origin Validation Error
VendorLangflow
ProductLangflow
CISA KEV AddedMay 21, 2026
Exploitation StatusActively exploited in the wild

Technical Analysis

Root Cause

Langflow's authentication system issues refresh tokens stored as browser cookies with the SameSite=None attribute. This attribute is intended for cross-site cookie sharing (e.g., embedded content), but when combined with Langflow's overly permissive CORS policy, it creates an attack pathway:

  1. SameSite=None — the refresh token cookie is sent with cross-origin requests
  2. Permissive CORS — Langflow's CORS configuration does not adequately restrict which origins can make credentialed requests
  3. Refresh endpoint exposure — an attacker-controlled page can trigger a cross-origin request to Langflow's /refresh endpoint, and the browser will automatically include the victim's refresh token cookie

The attacker receives a valid new access token from Langflow's server, effectively taking over the authenticated session without ever directly stealing the cookie value.

Attack Scenario

1. Victim is authenticated to a Langflow instance and visits a malicious webpage
2. Malicious page sends a cross-origin fetch() to https://victim-langflow.example.com/refresh
3. Browser automatically attaches the SameSite=None refresh token cookie
4. Langflow's permissive CORS policy allows the request and returns a new access token
5. Attacker receives the access token and gains full access to the victim's Langflow session
6. Attacker can read/modify AI workflows, extract API credentials stored in Langflow, and pivot

Why Langflow Is High-Value

Langflow is widely used to build and orchestrate AI agents and pipelines. A compromised Langflow session exposes:

  • AI workflow definitions — proprietary logic, prompt engineering, and automation flows
  • Stored API credentials — keys for OpenAI, Anthropic, vector databases, and other integrated services
  • Connected data sources — Langflow pipelines frequently process sensitive documents and structured data
  • Model configurations — fine-tuning parameters and system prompts

Impact Assessment

AreaRisk
Session HijackingFull authenticated access to the victim's Langflow instance
Credential TheftAPI keys stored in Langflow workflows are accessible to the attacker
Data ExfiltrationWorkflow inputs, outputs, and processed documents exposed
Workflow TamperingAttacker can modify or sabotage AI pipelines
Lateral MovementCompromised API keys enable attacks on downstream services

Remediation

Immediate Actions

  1. Apply the vendor patch — update Langflow to the version that addresses CVE-2025-34291 per the vendor's security advisory
  2. Restrict CORS origins — configure Langflow to only allow requests from explicitly trusted origins
  3. Rotate all stored API credentials — any API keys stored in Langflow should be rotated, particularly if the instance was publicly accessible
  4. Audit access logs — review Langflow access logs for unexpected cross-origin refresh token requests

Network Controls

  • Restrict Langflow access to VPN or internal networks — do not expose Langflow instances directly to the internet
  • Implement authentication at the reverse proxy layer — require SSO or client certificate authentication before Langflow is reachable
  • Monitor for anomalous session refresh activity — alert on refresh token usage from unexpected IP addresses or user agents

Review and apply the following cookie security attributes to all session-related cookies:

  • SameSite=Strict or SameSite=Lax (not None) for authentication cookies
  • HttpOnly to prevent JavaScript access
  • Secure to ensure HTTPS-only transmission
  • Explicit domain binding to prevent subdomain token theft

CISA KEV Entry

CISA added CVE-2025-34291 to the KEV catalog on May 21, 2026:

FieldValue
Vendor/ProjectLangflow
ProductLangflow
Vulnerability NameLangflow Origin Validation Error Vulnerability
Date Added2026-05-21
Required ActionApply mitigations per vendor instructions or discontinue use if mitigations are unavailable

References