ADVISORY UNAUTH-2026-0046
TYPE cve
PRODUCT Langflow
SEVERITY CRITICAL
Langflow CVE-2025-34291
published 2026-08-05 · updated 2026-08-05
Why it matters
CORS/CSRF chain: allow_origins='*' with credentials + SameSite=None refresh cookie lets a malicious page hijack a victim's session, then execute code via the validate endpoint. Account takeover → RCE. Actively exploited (CISA KEV). CVSS 9.4 (v4).
Affected versions
- <=1.6.9
Fixed in: latest (upgrade past 1.6.9 and review CORS settings)
Mapping provenance: human-verified against the linked advisory, last checked 2026-07-29. CISA KEV listed as actively exploited.
Fix it
References
Cite this record
unauth.dev advisory UNAUTH-2026-0046 — published 2026-08 · CC-BY 4.0
Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0046. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.