CVE-2025-34291Active Exploitation(langflow / langflow)

HIGHCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 12 mentions and remains active

Immediate actions

  • Patch langflow langflow systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.

7.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-06-04. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-346

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Active exploitation appears in 25 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 34 mentions across 14 observed days

What's happening

  • Active exploitation reported across 25 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 21 signals
  • General: 4 classified signals
  • Disclosure: 3 classified signals
  • Peaked 12d ago at 12 mentions (2026-05-22); latest day: 1
  • 34 total mentions across 14 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline34 mentions / 14d
036912Mentions · 2026-05-21: 6Mentions · 2026-05-22: 12Mentions · 2026-05-24: 3Mentions · 2026-05-25: 1Mentions · 2026-05-26: 3Mentions · 2026-05-27: 1Mentions · 2026-05-28: 1Mentions · 2026-05-30: 1Mentions · 2026-06-01: 1Mentions · 2026-06-04: 1Mentions · 2026-06-10: 1Mentions · 2026-06-15: 1Mentions · 2026-07-22: 1Mentions · 2026-08-13: 1PoC Mentioned / Linked · 2026-05-22: 1PoC Mentioned / Linked · 2026-05-24: 1PoC Mentioned / Linked · 2026-05-25: 1PoC Mentioned / Linked · 2026-08-13: 1Exploit Tool / Code · 2026-08-13: 1Active Exploitation · 2026-05-21: 3Active Exploitation · 2026-05-22: 10Active Exploitation · 2026-05-24: 2Active Exploitation · 2026-05-25: 1Active Exploitation · 2026-05-26: 2Active Exploitation · 2026-05-27: 1Active Exploitation · 2026-06-01: 1Active Exploitation · 2026-06-04: 1Active Exploitation · 2026-06-10: 1Active Exploitation · 2026-06-15: 1Active Exploitation · 2026-07-22: 1Active Exploitation · 2026-08-13: 1Patch / Workaround · 2026-05-21: 2Patch / Workaround · 2026-05-22: 4Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-05-26: 2Patch / Workaround · 2026-06-04: 1Patch / Workaround · 2026-06-10: 1Patch / Workaround · 2026-08-13: 1Technical Details · 2026-05-21: 3Technical Details · 2026-05-22: 7Technical Details · 2026-05-24: 1Technical Details · 2026-05-25: 1Technical Details · 2026-05-26: 2Technical Details · 2026-05-28: 1Technical Details · 2026-05-30: 1Technical Details · 2026-06-01: 1Technical Details · 2026-06-04: 1Technical Details · 2026-06-10: 1Technical Details · 2026-06-15: 1Technical Details · 2026-08-13: 105-2105-2205-2405-2505-2605-2705-2805-3006-0106-0406-1006-1507-2208-13
Signal classification4 categories
Active Exploitation
2573.5%
General
411.8%
Disclosure
38.8%
Patch
25.9%
Referenced assets40 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-216
Active Exploitation3Disclosure1General1Patch1
2026-05-2212
Active Exploitation10Disclosure1General1
2026-05-243
Active Exploitation2General1
2026-05-251
Active Exploitation1
2026-05-263
Active Exploitation2Patch1
2026-05-271
Active Exploitation1
2026-05-281
General1
2026-05-301
Disclosure1
2026-06-011
Active Exploitation1
2026-06-041
Active Exploitation1
2026-06-101
Active Exploitation1
2026-06-151
Active Exploitation1
2026-07-221
Active Exploitation1
2026-08-131
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 CISA just added two actively exploited vulns to its KEV catalog. https://thehackernews.com/2026/05/cisa-adds-exploited-langflow-and-trend.html Critical RCE in Langflow (CVE-2025-34291, CVSS 9.4) and directory traversal in Trend Micro Apex One (on-prem). Patch now if you're using either.

    Post summary

    CISA flagged CVE-2025-34291 and a Trend Micro Apex One directory traversal as actively exploited, urging immediate patching. The post provides key vulnerability details but no PoC or exploit code.

    39245311.8K
    1.9M followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Langflow origin validation error vulnerability CVE-2025-34291 and Trend Micro Apex One (on-premise) server directory traversal vulnerability CVE-2026-34926 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/Ii831YymYf

    Post summary

    The tweet announces that two CVEs, CVE-2025-34291 and CVE-2026-34926, have been added to a catalog of actively exploited threats, though no exploit code or patch details are provided.

    711230210.5K
    300.1K followersView on X
  • Zero Day Engineering@zerodayalpha
    Active Exploitation

    ⚡️ 0-Day Alert: IBM LangFlow OSS RCE LangFlow agent orchestration deployments have been under active exploitation since May. CVE-2025-34291: CORS misconfiguration + SameSite=None CVE-2026-33017*: Unauthenticated RCE via build_public_tmp's data parameter CVE-2026-55255: IDOR in /api/v1/responses: run any user's flow by ID CVE-2026-0770: Unauthenticated RCE via validate_code() / decorator abuse CVE-2026-9198: Unauthenticated RCE via auto_login + validate/code chain Bugs are not hard, likely spotted by generally available AI. Public exploit POCs exist. Majority takes input from an API endpoint variable and executes it directly on the OS. Attack pattern suggests that LangFlow has not seen basic security QA from the developer, and shouldn't be deployed in environments where arbitrary code execution poses a risk. * Attached: 33017 patch diff and code trace to exec()

    Post summary

    IBM LangFlow is suffering multiple CVEs, including active exploitation noted since May. Public exploit PoCs exist and a patch diff for CVE-2026-33017 is provided.

    17022103.2K
    11.8K followersView on X
  • AISecHub@AISecHub
    Active Exploitation

    AI Security Digest | May 18-24, 2026 🔴 ChromaDB: unauthenticated code execution NVD published CVE-2026-45829 for ChromaDB. The bug affects the ChromaDB Python project starting with version 1.0.0. An unauthenticated attacker can send a malicious model repository with trust_remote_code=true to the collections API endpoint and execute code on the server. HiddenLayer assigned the issue a CVSS 4.0 score of 10.0. 📌 https://nvd.nist.gov/vuln/detail/CVE-2026-45829
📌 https://www.hiddenlayer.com/research/chromatoast-served-pre-auth 🟠 Langflow: exploited vulnerability added to CISA KEV CISA added CVE-2025-34291 in Langflow to the Known Exploited Vulnerabilities catalog on May 21. The vulnerability affects Langflow versions up to and including 1.6.9. NVD describes it as a chained issue involving permissive CORS and refresh-token cookie behavior that can lead to account takeover and remote code execution. 📌 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34291
📌 https://nvd.nist.gov/vuln/detail/CVE-2025-34291
📌 https://github.com/advisories/GHSA-577h-p2hh-v4mv 🧪 Anthropic: Mythos used for vulnerability discovery Reuters reported that Anthropic planned to brief the Financial Stability Board on vulnerabilities identified by Claude Mythos. Anthropic also published a disclosure dashboard showing 1,596 vulnerabilities disclosed across 281 open-source projects as of May 22. 📌 https://www.reuters.com/technology/anthropic-brief-financial-stability-board-cyber-flaws-exposed-by-mythos-ft-2026-05-18/
📌 https://red.anthropic.com/2026/cvd/
📌 https://www.anthropic.com/research/glasswing-initial-update 🦊 Mozilla: Firefox bugs found during Claude Mythos evaluation Mozilla published details on its work with Anthropic’s Claude Mythos. Firefox 150 included fixes for vulnerabilities identified during the evaluation, grouped under CVE-2026-6784, CVE-2026-6785, and CVE-2026-6786. 📌 https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/
📌 https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/ #AISecurity #CyberSecurity #AISECHUB #ChromaDB #Langflow #CISA #Anthropic #Mythos #Mozilla #Firefox #LLMSecurity

    Post summary

    The digest highlights newly disclosed critical vulnerabilities—particularly CISA’s KEV listing for Langflow—indicating real‑world exploitation, while also providing PoC links and technical details for other CVEs.

    140821.0K
    9.3K followersView on X
  • WhiskeyHacker@whiskeyhacker
    Patch

    CISA added Langflow CVE-2025-34291 to KEV on May 21. Federal patch deadline June 4. Attribution: MuddyWater. Same MOIS team that pre-positioned Stryker before Handala fired the bulk Intune wipe in March. We have tracked this crew across six briefs. Thread on the new front.

    Post summary

    CISA added CVE-2025-34291 to its KEV list with a June 4 federal patch deadline, but no PoC, exploit, or detailed technical data is provided.

    11020725
    4.2K followersView on X
  • Ahmad Sadeddin@asadeddin
    Disclosure

    🏮 Hot off the press: 3 new vulnerability research articles that everyone should read: - art-template npm compromise delivered a Coruna-like iOS exploit kit (Critical 🔴) - CVE-2025-34291: Langflow CORS and refresh-token chain reaches RCE (Critical 🔴) - CVE-2026-46333: Linux ptrace race leaks privileged file descriptors (High 🟠 ) https://corgea.com/research

    Post summary

    The post highlights three recent vulnerability research articles: an iOS exploit kit, an RCE in Langflow via CORS/refresh-token leakage, and a Linux ptrace race that leaks privileged file descriptors.

    110201.2K
    951 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-42945 2 - CVE-2026-46333 3 - CVE-2026-9082 4 - CVE-2026-31431 5 - CVE-2025-34291 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet lists five trending CVE IDs without providing additional context, PoC, exploitation, patch, or technical details.

    00031714
    1.7K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    CISA updates its KEV Catalog with critical flaws in Langflow (CVE-2025-34291) and Trend Micro Apex One. Federal agencies ordered to patch by June 4, 2026. #CISAKEV #Langflow #TrendMicro #ThreatIntel #Vulnerability #AIsecurity #CORSbypass #RCE #SysAdmin https://securityonline.info/cisa-kev-catalog-langflow-cve-2025-34291-trend-micro/ https://t.co/YsDOV0ZK5B

    Post summary

    CISA’s KEV Catalog now lists CVE-2025-34291 for Langflow, with federal agencies mandated to patch by June 4, 2026, underscoring the flaw’s critical severity while offering no details on exploitation or technical specifics.

    010211.2K
    12.5K followersView on X
  • CloudSecurityAlliance@cloudsa
    Active Exploitation

    CISO Daily Briefing: SLSA Build Level 3 provenance defeated — Shai-Hulud/Megalodon backdoored 5,561 repos in 6 hours via stolen OIDC tokens, breaching OpenAI employee devices and Grafana Labs internal repos; Langflow CVE-2025-34291 (CVSS 9.4) is the first AI orchestration platform to hit CISA KEV — audit LangChain, n8n, CrewAI, Flowise now; Five Eyes agentic AI guidance addresses privilege creep and audit gaps; one campaign can now degrade both your AI ops and your AI-enabled defenses simultaneously. https://labs.cloudsecurityalliance.org/research/ciso-daily-briefing-20260522/

    Post summary

    The briefing states that Langflow’s CVE-2025-34291 has entered the CISA KEV list, indicating it is actively exploited, and urges auditors to review related AI orchestration platforms.

    10011869
    18.7K followersView on X
  • Adam@seoscottsdale
    Active Exploitation

    Supply-chain surge status as of May 26, 2026 – 100% verified accuracy on Ghost CMS CVE-2026-26980 mass exploitation, Laravel Lang hijack, healthcare vendor breaches & CISA KEV additions; surge accelerating with no new catastrophic incidents in last 48h. 🚨 SUPPLY CHAIN CYBER ATTACK SURGE – MAY 26, 2026 X ARTICLE (100% LIVE-VERIFIED)
Ghost CMS actively exploited on 700+ sites. Laravel Lang packages poisoned. Healthcare vendors leaking PHI. CISA drops fresh KEVs. Accuracy Verdict: 100% Confirmed — Full independent fact-check against BleepingComputer, HIPAA Journal, CISA & threat intel sources. Zero discrepancies. Ready-to-post early-warning for @seoscottsdale & every Arizona team. High-signal facts + urgent actions only. Thread 🧵
#SupplyChainAttack #CyberSecurity #ScottsdaleCyber #PhoenixInfoSec #ArizonaTech 1/9
✅ Ghost CMS CVE-2026-26980 – Mass Exploitation LIVE
Critical SQL injection actively exploited on 700+ sites. Attackers steal Admin API keys → inject malicious JS that triggers ClickFix malware (fake Cloudflare CAPTCHA → PowerShell execution).
Affected: Academia, SaaS, media, fintech.
Severity: High & ongoing.
Source: BleepingComputer (May 24-25, 2026).
Action: Patch immediately + full site integrity audit. 2/9
✅ Laravel Lang Supply-Chain Hijack
Attackers rewrote GitHub version tags to push malicious Composer packages packed with credential-stealing malware.
Affected: Any dev/org using Laravel localization packages.
Impact: Downstream app compromises at scale.
Timeline: May 22-23, 2026.
Source: BleepingComputer.
Action: Audit every Composer dependency and verify signatures NOW. 3/9
✅ Healthcare Vendor & HIPAA Supply-Chain Breaches
• Lumexa Imaging vendor incident
• Radiology Associates of Richmond (266K records exposed) + multiple covered entities
Arizona impact: Scottsdale/Phoenix hospitals, clinics & imaging centers using third-party vendors are in the direct blast radius (HIPAA + AZ breach laws).
Source: HIPAA Journal (May 19-20, 2026). 4/9
✅ CISA Known Exploited Vulnerabilities (KEV) Catalog Updates
Recent additions:
• May 21: CVE-2025-34291 (Langflow) + CVE-2026-34926 (Trend Micro Apex One)
• May 7: CVE-2026-6973 (Ivanti EPMM)
Affected: Federal contractors & enterprises.
Severity: Mandatory patching under BOD 22-01 or face enforcement.
Source: http://CISA.gov/news-events/alerts/ (May 2026). 5/9
✅ Broader Context (SentinelOne & CrowdStrike intel)
No brand-new catastrophic incident in the last 48 hours, but persistent open-source activity (npm/PyPI waves) + active Ghost CMS and Laravel vectors keep the 2026 supply-chain surge elevated. 6/9
Scottsdale/Phoenix 24-Hour Action Checklist 1Run full SBOM scan on every environment 2Audit all CMS, Composer, npm & PyPI dependencies 3Review third-party vendor access & contracts 4Patch every KEV immediately 5Test supply-chain incident response playbooks 7/9
These upstream attacks hit Arizona healthcare, tech firms, SaaS teams, and government contractors the hardest.
The surge isn’t coming — it’s here right now. 8/9
Full Verified Deep-Dive Available
This entire briefing was built live from primary sources and independently accuracy-checked as of 08:35 AM PDT today.
Subscribe for weekly GEO-optimized cyber briefings tailored to the greater Phoenix metro. 9/9
What’s your #1 supply-chain risk right now? Drop it in the replies 👇
RT to protect your network and the Phoenix metro.
@seoscottsdale #InfoSec #ThirdPartyRisk #CyberSurge2026 #ArizonaCyber End of Verified X Article – 100% accurate & ready to post. Stay ahead. Protect the chain.
Sources (all checked live May 26, 2026): http://BleepingComputer.com (May 23–25), http://HIPAAJournal.com (May 19–20), http://CISA.gov (May 2026), SentinelOne & CrowdStrike blogs.

    Post summary

    The thread reports that Ghost CMS CVE‑2026‑26980 is being actively exploited on 700+ sites via critical SQL injection, and stresses immediate patching along with broader supply‑chain hygiene.

    01010134
    12.4K followersView on X
  • ThreatLevel@ThreatLevelAI
    Active Exploitation

    🚨 Authentication Bypass → Remote Code Execution in Langflow added to the CISA Known Exploited Vulnerabilities catalog (CVE-2025-34291). Active exploitation confirmed. Patch immediately. More details 👇 https://t.co/8HFUZocq5R

    Post summary

    CVE-2025-34291 in Langflow is confirmed to be actively exploited via an authentication bypass that allows remote code execution; a patch is available immediately.

    10010685
    7 followersView on X
  • ThaiCERT By NCSA@ThaiCERTByNCSA
    Active Exploitation

    🛑 ด่วน! แจ้งเตือนช่องโหว่ร้ายแรงใน Langflow 🛑 ⚠️ ศูนย์ประสานการรักษาความมั่นคงปลอดภัยระบบคอมพิวเตอร์แห่งชาติ (ThaiCERT) ได้ติดตามสถานการณ์ภัยคุกคามทางไซเบอร์ และพบประกาศด้านความปลอดภัยจาก Cyber Security Agency of Singapore (CSA) เกี่ยวกับช่องโหว่ร้ายแรง CVE-2025-34291 ใน Langflow ซึ่งเป็นแพลตฟอร์มสำหรับสร้างและใช้งาน AI-powered agents และ workflows โดย CSA ระบุว่าช่องโหว่นี้ถูกค้นพบตั้งแต่เดือนธันวาคม 2025 และขณะนี้มีการนำไปใช้โจมตีจริงแล้ว ผู้ใช้งานและผู้ดูแลระบบที่ใช้งาน Langflow เวอร์ชันที่ได้รับผลกระทบควรอัปเดตเป็นเวอร์ชันล่าสุดโดยทันที [1] 1. รายละเอียดช่องโหว่ CVE-2025-34291 - Langflow Origin Validation Error Vulnerability / Account Takeover and Remote Code Execution (RCE) (CVSS v3.1: 8.8 )[2] ช่องโหว่นี้เกิดจากข้อผิดพลาดด้านการตรวจสอบ Origin รวมถึงการตั้งค่า CORS ที่เปิดกว้างเกินไป เช่น การอนุญาต allow_origins='*' พร้อมกับ allow_credentials=True ร่วมกับ refresh token cookie ที่กำหนดเป็น SameSite=None ทำให้เว็บไซต์ที่ผู้โจมตีควบคุมสามารถส่งคำขอข้าม Origin พร้อมข้อมูลรับรองของผู้ใช้งานได้ในบางเงื่อนไข หากโจมตีสำเร็จ ผู้ไม่หวังดีอาจได้รับ access token / refresh token ของ session ผู้ใช้งาน และนำ token ดังกล่าวไปเข้าถึง endpoint ที่ต้องยืนยันตัวตน รวมถึงฟังก์ชันที่เกี่ยวข้องกับการรันโค้ดใน Langflow ส่งผลให้สามารถสั่งรันโค้ดยึดครองบัญชีผู้ใช้งาน และอาจนำไปสู่การยึดครองระบบได้ทั้งหมด 2. ผลิตภัณฑ์ที่ได้รับผลกระทบ[3] Langflow เวอร์ชัน 1.6.9 และเวอร์ชันก่อนหน้า 3. แนวทางการแก้ไข 3.1 ผู้ใช้งานและผู้ดูแลระบบที่ใช้งาน Langflow เวอร์ชัน 1.6.9 หรือต่ำกว่า ควรอัปเดตเป็นเวอร์ชันล่าสุดโดยทันที ตามคำแนะนำของ CSA 3.2 ตรวจสอบระบบที่ติดตั้ง Langflow ทั้งหมด โดยเฉพาะระบบที่เปิดให้เข้าถึงผ่านอินเทอร์เน็ต หรือระบบที่มีผู้ใช้งานหลายบัญชี 3.3 หลังอัปเดต ควรตรวจสอบการตั้งค่า CORS และการจัดการ cookie/session ให้สอดคล้องกับแนวทางความปลอดภัย โดยหลีกเลี่ยงการอนุญาต Origin แบบกว้างเกินความจำเป็น 3.4 พิจารณาเพิกถอนหรือหมุนเวียน token, API key, credential, secret และค่าเชื่อมต่อสำคัญที่จัดเก็บหรือใช้งานผ่าน Langflow หากสงสัยว่าระบบเคยถูกเข้าถึงโดยไม่ได้รับอนุญาต 4. แนวทางลดความเสี่ยง 4.1 จำกัดการเข้าถึง Langflow จากอินเทอร์เน็ตเท่าที่จำเป็น และควรให้เข้าถึงผ่าน VPN, Zero Trust Access, reverse proxy หรือเครือข่ายภายในที่ควบคุมได้ 4.2 ตรวจสอบ log และพฤติกรรมผิดปกติที่เกี่ยวข้องกับการขอ refresh token, การใช้งาน session ที่ผิดปกติ, การเรียกใช้งาน endpoint สำคัญ และการรันโค้ดภายใน Langflow 4.3 ตรวจสอบบัญชีผู้ใช้งานใน Langflow ว่ามีการสร้างบัญชีใหม่ เปลี่ยนสิทธิ์ หรือมี activity ที่ไม่สอดคล้องกับการใช้งานปกติหรือไม่ 4.4 หากยังไม่สามารถอัปเดตได้ทันที ให้จำกัดสิทธิ์การใช้งาน Langflow เฉพาะผู้ใช้ที่จำเป็น ปิดการเข้าถึงจากเครือข่ายภายนอก และเพิ่มการตรวจจับผ่าน WAF / reverse proxy / SIEM 4.5 แจ้งเตือนผู้ใช้งานไม่ให้เปิดลิงก์หรือเว็บไซต์ที่ไม่น่าเชื่อถือในขณะที่ยังมี session ใช้งาน Langflow อยู่ เนื่องจากลักษณะช่องโหว่เกี่ยวข้องกับการส่งคำขอข้าม Origin ผ่าน browser session ของผู้ใช้งาน 4.6 ผู้ดูแลระบบควรติดตามประกาศจาก CSA, GitHub Advisory, NVD และผู้พัฒนา Langflow อย่างใกล้ชิด เพื่อรับทราบคำแนะนำด้านแพตช์และมาตรการบรรเทาผลกระทบล่าสุด แหล่งอ้างอิง [1] https://dg.th/bdesg19iwx [2] https://dg.th/x4f3ez7wdb [3] https://dg.th/qi4hezjfgo

    Post summary

    The advisory confirms CVE‑2025‑34291 in Langflow is actively exploited, outlines severe technical details, and urges immediate patching and mitigation.

    00001155
    55 followersView on X
  • Proficio@proficioinc
    Active Exploitation

    U.S. CISA adds Trend Micro Apex One (CVE-2026-34926) and Langflow (CVE-2025-34291) to Known Exploited Vulnerabilities catalog via @SecurityAffairs #Proficio #ThreatNews #Cybersecurity #MSSP #MDR https://securityaffairs.com/192529/hacking/u-s-cisa-adds-trend-micro-apex-one-and-langflow-to-its-known-exploited-vulnerabilities-catalog.html

    Post summary

    The article reports that CVE-2026-34926 and CVE-2025-34291 have been cataloged by U.S. CISA as known exploited vulnerabilities, indicating real‑world exploitation activity.

    00010137
    1.0K followersView on X
  • كاسبر سكاي@KasperskyDev
    Active Exploitation

    CISA أضافت CVE-2025-34291 في Langflow لقائمة KEV بعد استغلال موثّق يُنسب لمجموعة MuddyWater. الثغرة (CVSS 9.4) تجمع CORS مفتوحة بزيادة CSRF للوصول لـ refresh endpoint وتنفيذ arbitrary code بصلاحيات عالية. مهلة الوكالات الفيدرالية 4 يونيو. #CVE-2025-34291 #Langflow

    Post summary

    CISA added CVE-2025-34291 to the KEV list following documented exploitation by MuddyWater, underscoring a high‑severity Langflow flaw that merges open CORS and CSRF to run arbitrary code with elevated privileges.

    10000244
    40.0K followersView on X
  • Hephaestvs@Vulcanux_
    Active Exploitation

    csirt_it: ‼️#Langflow: rilevato sfruttamento della CVE-2025-34291 Rischio: 🔴 Tipologia 🔸 Remote Code Execution 🔗 https://www.acn.gov.it/portale/w/langflow-rilevato-sfruttamento-della-cve-2025-34291 ⚠ Importante aggiornare i prodotti interessati https://t.co/5u5DRZzloH

    Post summary

    The CVE-2025-34291 vulnerability, a remote code execution flaw, has been actively exploited in the wild and users are advised to apply available updates.

    00010677
    614 followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(5/21追加) 🛡️No.1601 CVE-2025-34291 Langflow Origin Validation Error Vulnerability ==================================== ✅概要 ・深刻度:重要 8.8 (CVSS Base) / NVD ・種別:同一生成元ポリシー違反 (CWE-346) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Langflow 1.6.9 以下には、過度に許可された CORS 設定と SameSite=None の refresh token cookie の組み合わせにより、アカウント乗っ取りとリモートコード実行に至る連鎖的な脆弱性が存在します。攻撃者は悪意ある Web ページから被害者セッションに対してクロスオリジン要求を送信し、新しい access token / refresh token を取得できます。取得したトークンで認証済みエンドポイントに到達でき、組み込みのコード実行機能を通じて任意コード実行と全面的なシステム侵害に至る恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・Langflow 1.6.9 以下が稼働していること。 ・標的が Langflow にログイン済みのセッションを保持していること。 ・標的が悪意ある Web ページを閲覧すること。 ・過度に許可された CORS 設定と SameSite=None の refresh token cookie 設定が有効であること。 ✅悪用時影響 ・被害者セッションの fresh access token / refresh token を取得される ・認証済みエンドポイントへ不正アクセスされる ・組み込みのコード実行機能を悪用され、任意のコードを実行される ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。CrowdSec は 2026年1月23日から本脆弱性のアクティブな悪用を観測したと報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-34291 https://github.com/langflow-ai/langflow https://www.crowdsec.net/vulntracking-report/cve-2025-34291 🛡️No.1602 CVE-2026-34926 Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability ==================================== ・関連ポスト済 https://x.com/piyokango/status/2057634002895540274 https://www.cisa.gov/news-events/alerts/2026/05/21/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The text announces that CVE‑2025‑34291 has been added to CISA’s KEV catalog, provides the technical details of the flaw, notes that a partial PoC is publicly available, and confirms that active exploitation has been observed by CrowdSec.

    000106.1K
    43.3K followersView on X
  • z3n@zench4n
    Active Exploitation

    Critical updates: Langflow (CVE-2025-34291) is now on the CISA KEV. For teams building agentic RAG pipelines, this is a massive signal. Unpatched orchestration layers are low-hanging fruit for lateral movement. Audit your agentic frameworks immediately.

    Post summary

    Langflow’s vulnerability CVE-2025-34291 is listed on the CISA KEV, signaling active exploitation and urging immediate audit of agentic RAG pipelines.

    10000596
    1.4K followersView on X
  • Cyphere@TheCyphere
    Active Exploitation

    CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-34291 Langflow Origin Validation Error Vulnerability CVE-2026-3492 @CISACyber

    Post summary

    CISA added CVE-2025-34291 and CVE-2026-3492 to its KEV catalog, citing evidence of active exploitation.

    0000050
    1.5K followersView on X
  • SHORT INFO@ShortInfoNews
    Active Exploitation

    Any unpatched Langflow instance is being scanned by Iranian APT MuddyWater right now. CVE-2025-34291 (CVSS 9.4) chains a CORS flaw, missing CSRF, and a code-exec endpoint into full RCE plus exfil of every API key. CISA KEV deadline June 4.

    Post summary

    The post warns that unpatched Langflow instances are actively being scanned and exploited by the Iranian APT MuddyWater, with the CVE‑2025‑34291 allowing full RCE and key exfiltration, and highlights an imminent CISA KEV deadline.

    0000042
    152 followersView on X
  • CyberAlertsHQ@CyberAlertsHQ
    Active Exploitation

    🚨 UPDATE — Langflow CVE-2026-5027: This is now the 5th Langflow CVE exploited in 2026. A CISA KEV listing is expected imminently — a prior Langflow RCE (CVE-2025-34291) was added to KEV on May 21 with Iranian APT MuddyWater confirmed in attacks. Key pattern: Langflow stores API tokens and credentials for every integrated downstream service. Compromising it triggers a cascade across all connected SaaS environments. VulnCheck confirms exploitation of test-file writes already underway — that's reconnaissance ahead of full RCE. Patch to v1.10.0 now. Don't wait for KEV confirmation. 👇 https://www.bleepingcomputer.com/news/security/path-traversal-flaw-in-ai-dev-platform-langflow-exploited-in-attacks/

    Post summary

    CVE-2026-5027 in Langflow is being actively exploited via a path‑traversal flaw that allows credential compromise across connected SaaS services; a patch (v1.10.0) is available and a CISA KEV listing is pending.

    0000086
    77 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more