Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
How Tier 1 Can Process Alerts 3x Faster with Threat Intel
May 26, 2026
Angular Language Service Flaws Enable Remote Code Execution
May 26, 2026
Quasar Linux RAT Targets Developers via Fileless eBPF
May 26, 2026
Home/CyberSecurity News/CISA Adds Langflow Flaw to Exploited Vulner Origin Validation
CyberSecurity News

CISA Adds Langflow Flaw to Exploited Vulner Origin Validation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Langflow vulnerability, CVE-2025-34291, to its Known Exploited Vulnerabilities (KEV) Catalog. This move signals...

Jennifer sherman
Jennifer sherman
May 22, 2026 2 Min Read
17 0

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Langflow vulnerability, CVE-2025-34291, to its Known Exploited Vulnerabilities (KEV) Catalog. This move signals active exploitation and mandates immediate remediation for affected organizations.

The flaw affects Langflow, a popular tool used for building and deploying AI-driven workflows. The issue stems from an origin validation error caused by an overly permissive Cross-Origin Resource Sharing (CORS) configuration.

When combined with a refresh token cookie configured as SameSite=None, the vulnerability allows malicious websites to perform authenticated cross-origin requests.

This weakness enables attackers to:

  • Send unauthorized requests from a victim’s browser.
  • Access sensitive refresh tokens
  • Call backend authentication endpoints.
  • Potentially execute arbitrary code.
  • Achieve full system compromise.

Langflow Origin Validation Flaw

The vulnerability is categorized under CWE-346 (Origin Validation Error), highlighting improper validation of request origins.

In practical terms, an attacker can trick a user into visiting a malicious webpage. Because of the flawed CORS policy and cookie configuration, the victim’s browser automatically includes authentication credentials in cross-origin requests.

This allows the attacker to silently interact with Langflow’s API, particularly the refresh endpoint, without user awareness.

Once refresh tokens are obtained, attackers can:

  • Generate new access tokens.
  • Maintain persistent access.
  • Interact with authenticated endpoints.
  • Escalate privileges within the system.

This type of attack is especially dangerous in environments where Langflow is integrated with AI pipelines, APIs, or cloud-based services.

CISA added CVE-2025-34291 to its KEV catalog on May 21, 2026, confirming that the vulnerability poses a significant threat to federal and enterprise systems.

Federal Civilian Executive Branch (FCEB) agencies are required to remediate the vulnerability by the due date under Binding Operational Directive (BOD) 22-01.

CISA strongly advises organizations to take immediate action:

  • Apply vendor-provided patches or updates without delay.
  • Review and restrict CORS configurations to trusted origins only.
  • Avoid using SameSite=None for sensitive authentication cookies unless necessary.
  • Implement additional protections such as CSRF tokens and strict origin validation.
  • Monitor logs for suspicious cross-origin requests and token abuse.
  • Discontinue use of Langflow if mitigations are not available.

Organizations using Langflow in production environments, especially those handling sensitive data or AI workflows, should prioritize this vulnerability given its potential to compromise the entire system.

The inclusion of this flaw in the KEV catalog underscores the growing risk of misconfigured web security controls in modern applications.

As AI platforms like Langflow become more widely adopted, attackers are increasingly targeting weaknesses in authentication flows and API security.

Security teams should treat CVE-2025-34291 as a high-priority issue and implement rapid mitigations to prevent unauthorized access and potential breaches.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVECybersecurityExploitPatchSecurityThreatVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

CISA Warns: Microsoft Defender 0-Day Vulnerabilities Exploited

Next Post

Deleted Google API Keys Still Access Gemini, BigQuery,

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft Defender Isolates Compromised Devices from Ransom
May 26, 2026
GitHub Down: Authentication Issues Deny Access to Actions
May 26, 2026
Hackers Exploit Ghost CMS CVE-2026 CVE-2026-26980 Poison
May 26, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us