Skip to content
Briefings are running a touch slower this week while we rebuild the foundations.See roadmap
Timeline

CVE-2025-34291

Origin-validation flaw (CVSS 9.4) in Langflow combining permissive CORS, missing CSRF protection and a code-execution endpoint.

1 of 1 entries (1 events, 0 interactions)

Filters
#521 May

Mentioned in: AI orchestration flaw joins CISA's KEV

Cybersecurity: Threats and Defences