Exploited Vulnerabilities Daily
🌐 日本語

ホーム › Langflow

CVE-2025-34291: Langflow Langflow

EPSS92.8%KEV 1739件中417位
CVEの年2025追加まで約1年
同じベンダーの登録5
同じ製品の登録5
項目内容
ベンダーLangflow
製品Langflow
脆弱性の名前Langflow Origin Validation Error Vulnerability
KEVへの追加日2026年5月21日
米政府機関の対応期限2026年6月4日
ランサムウェアでの悪用不明
CWECWE-346

CISAの説明(英語)

Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.

同じ製品のほかの登録

CVEベンダー・製品追加日EPSSランサムウェア
CVE-2026-0770Langflow Langflow2026年7月21日63.0%不明
CVE-2026-55255Langflow Langflow2026年7月7日0.8%不明
CVE-2026-33017Langflow Langflow2026年3月25日24.7%不明
CVE-2025-3248Langflow Langflow2025年5月5日99.9%確認あり

NVD — CVE-2025-34291

CISAの既知の悪用された脆弱性カタログ(KEV)のデータです。EPSSはFIRSTが公表する「今後30日以内に悪用が観測される確率」の推定値で、週1回更新しています。対応は必ず各ベンダーの公式情報に従ってください。
このページについて

2026年5月21日にCISAの既知の悪用された脆弱性カタログ(KEV)に追加された、LangflowのLangflowの脆弱性です。