logo

CISA adds Langflow Origin Validation Flaw to Known Exploited Vulnerabilities Catalog

ID: 87edbdd1-52b7-5397-bb7f-952234836fdd

STIX ID: report--87edbdd1-52b7-5397-bb7f-952234836fdd

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Abinaya

...
...

CISA added CVE-2025-34291 — a Langflow origin validation/CORS flaw that, when combined with SameSite=None refresh cookies, enables authenticated cross-origin requests and theft of refresh tokens — to its Known Exploited Vulnerabilities catalog, warning of active exploitation and urging immediate remediation (patches, restrictive CORS, avoiding SameSite=None, CSRF protections, monitoring, or discontinuation).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.