CVE-2025-34291: Langflow Langflow
EPSS92.8%KEV 1739件中417位
CVEの年2025追加まで約1年
同じベンダーの登録5
同じ製品の登録5
| 項目 | 内容 |
|---|---|
| ベンダー | Langflow |
| 製品 | Langflow |
| 脆弱性の名前 | Langflow Origin Validation Error Vulnerability |
| KEVへの追加日 | 2026年5月21日 |
| 米政府機関の対応期限 | 2026年6月4日 |
| ランサムウェアでの悪用 | 不明 |
| CWE | CWE-346 |
CISAの説明(英語)
Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.
同じ製品のほかの登録
| CVE | ベンダー・製品 | 追加日 | EPSS | ランサムウェア |
|---|---|---|---|---|
| CVE-2026-0770 | Langflow Langflow | 2026年7月21日 | 63.0% | 不明 |
| CVE-2026-55255 | Langflow Langflow | 2026年7月7日 | 0.8% | 不明 |
| CVE-2026-33017 | Langflow Langflow | 2026年3月25日 | 24.7% | 不明 |
| CVE-2025-3248 | Langflow Langflow | 2025年5月5日 | 99.9% | 確認あり |
CISAの既知の悪用された脆弱性カタログ(KEV)のデータです。EPSSはFIRSTが公表する「今後30日以内に悪用が観測される確率」の推定値で、週1回更新しています。対応は必ず各ベンダーの公式情報に従ってください。
このページについて
2026年5月21日にCISAの既知の悪用された脆弱性カタログ(KEV)に追加された、LangflowのLangflowの脆弱性です。