logo

Critical CVE-2025-34291 in Langflow AI Agent Under Active Exploitation

ID: 22eed5df-13d4-5464-8cc3-d4358fa38d4a

STIX ID: report--22eed5df-13d4-5464-8cc3-d4358fa38d4a

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-05-30

Date Updated: 2026-05-30

...
...

CVE-2025-34291 is a critical remote code execution and account takeover vulnerability in Langflow (affecting versions 1.6.9 and earlier) with a CVSS v4.0 score of 9.4; a public PoC and active exploitation have been reported and the issue has been added to CISA's Known Exploited Vulnerabilities catalog, prompting urgent recommendations to update Langflow, harden CORS policies, and review authentication cookie configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.