AI Stories on SHORT INFO are generated & curated with AI
unverified 15 Jun, 09:09

Iranian APT MuddyWater actively exploits Langflow CVE-2025-34291 (CVSS 9.4) - CISA KEV

Any unpatched Langflow instance is being scanned by Iranian APT MuddyWater right now. CVE-2025-34291 (CVSS 9.4) gives full code execution and exposes every API key in the workspace, cascading into connected cloud services. CISA has set the federal patch deadline at June 4.

Any organization still running an unpatched Langflow instance is being scanned by Iranian state-sponsored attackers right now. CISA added CVE-2025-34291 to its Known Exploited Vulnerabilities catalog this week, citing active exploitation by MuddyWater, an Iran-nexus APT group. The flaw carries a CVSS score of 9.4 and chains three weaknesses: an overly permissive CORS configuration, missing CSRF protection, and an endpoint designed to allow code execution. Combined, those weaknesses give a remote attacker full code execution on the Langflow server. Once inside, the attacker walks away with every access token and API key stored in the workspace. Because Langflow is widely used as a hub for AI agent workflows that connect to cloud platforms, databases, and SaaS tools, a single compromised instance cascades into every downstream service it touches. CISA paired the alert with a second KEV entry: Trend Micro Apex One on-premise CVE-2026-34926, a directory traversal flaw observed in active exploitation that allows a local attacker with admin credentials to inject malicious code and push it to all managed agents. Federal civilian agencies have until June 4 to patch. Private operators should treat the deadline as their own. Audit any Langflow deployment exposed to the internet, rotate every credential the workspace has ever held, and check for indicators of compromise consistent with MuddyWater tradecraft.

Published on
ThreadsXBlueskyFacebook