Langflow < 1.7.0 CORS設定ミスのアカウント乗っ取りとRCE(CVE-2025-34291)

critical Nessus プラグイン ID 317391

バージョン 1.2

May 29, 2026, 5:27 PM

  • CISA reference
  • CVSS metrics ("Cvssv4 score" set to 9.4. "Cvssv4 threat vector" set to "CVSS:4.0/E:A". "Cvssv4 vector" set to "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H")
  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:F/RL:OF/RC:C". "CVSSv3 temporal vector" set to "CVSS:3.0/E:F/RL:O/RC:C")
  • Exploit attributes ("Exploit available" set to "True". "Exploitability ease" set to "Exploits are available")
  • New

Plugin Feed: 202605291727