CVE-2025-34291

KEV
🔴 Łataj teraz

Luka w Langflow umożliwia przejęcie konta i zdalne wykonanie kodu.

CVSS
8.8
EPSS
34.1%
Exploit
weaponized
Vendor
langflow
Opis źródłowy (NVD)

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.

exploit rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.8
CISA KEV (aktywnie wykorzystywane)Tak
FIRST EPSS (prawdopodobieństwo exploita)34.1%
Opublikowano (NVD)2025-12-05 23:15:47 UTC
Ostatnia modyfikacja (NVD)2026-05-21 20:16:13 UTC
Referencje