Langflow AI versions 1.6.9 and earlier are vulnerable to a CORS misconfiguration that allows any origin to make credentialed requests. Combined with SameSite=None cookies, this enables cross-origin token theft and subsequent remote code execution via the /api/v1/validate/code endpoint.
id: CVE-2025-34291
info:
name: Langflow AI <= 1.6.9 - CORS Misconfiguration
author: 686f6c61
...