CISA adds Langflow Origin Validation Flaw to Known Exploited Vulnerabilities Catalog
ID: 87edbdd1-52b7-5397-bb7f-952234836fdd
STIX ID: report--87edbdd1-52b7-5397-bb7f-952234836fdd
Feed Name: cybersecurityNews.com
Threat Score
CISA added CVE-2025-34291 — a Langflow origin validation/CORS flaw that, when combined with SameSite=None refresh cookies, enables authenticated cross-origin requests and theft of refresh tokens — to its Known Exploited Vulnerabilities catalog, warning of active exploitation and urging immediate remediation (patches, restrictive CORS, avoiding SameSite=None, CSRF protections, monitoring, or discontinuation).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
