www.cisa.gov 5/21/2026, 9:19:46 PM · external

CISA warns of critical Langflow CVE-2025-34291 flaw under attack

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown

THE **Known Exploited Vulnerabilities Catalog** maintained by CISA provides an authoritative source for vulnerabilities that have been exploited in the wild, aiding organizations in prioritizing their vulnerability management frameworks. One notable entry is **CVE-2025-34291**, which relates to an origin validation error in the Langflow application, potentially allowing attackers to perform cross-origin requests with credentials, leading to system compromise.

Organizations are encouraged to apply necessary mitigations and can access the catalog in various formats (CSV, JSON, Print View). Additionally, there's an option to nominate new vulnerabilities and subscribe for updates.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline