CISA adds Langflow Vulnerability to Known Exploited Vulnerabilities Catalog
ID: 43f996d9-1bda-5b42-b28b-5dba5ae75318
STIX ID: report--43f996d9-1bda-5b42-b28b-5dba5ae75318
Feed Name: Cyber Press
Threat Score
**CISA added CVE-2025-34291 (Langflow) to the KEV Catalog due to active exploitation: a CORS/origin validation flaw plus a SameSite=None refresh cookie can enable cross-origin token theft and remote code execution; administrators should apply patches, restrict CORS, and reconfigure cookies before the federal remediation deadline of June 4, 2026.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
