AI Stories on SHORT INFO are generated & curated with AI
unverified 23 May, 05:10

Langflow CVE-2025-34291 actively exploited by Iran's MuddyWater APT, CISA KEV adds with June 4 federal patch deadline

Every Langflow install on version 1.6.9 or older is being targeted by Iran's MuddyWater APT. CISA added CVE-2025-34291 to its KEV catalog May 21. The flaw chains permissive CORS with a CSRF gap on a code-execution endpoint, enabling account takeover and RCE. Federal patch deadlin

Every Langflow install running version 1.6.9 or older is exposed to active exploitation by Iran-linked APT group MuddyWater right now, according to CISA's update on May 21. The agency added CVE-2025-34291 to its Known Exploited Vulnerabilities catalog with a CVSS score of 9.4. The flaw chains three weaknesses inside Langflow: an overly permissive Cross-Origin Resource Sharing policy, a missing CSRF check, and an endpoint that by design allows code execution. Together they enable a remote attacker to take over user accounts and run arbitrary code on the host. Langflow is the open-source orchestrator that many teams use to build and run AI agent workflows. A successful exploit gives the attacker the same level of access the workflow itself has, including any model API keys, internal service tokens, and database connections wired into the agent. Federal Civilian Executive Branch agencies have a hard deadline of June 4 to patch. Private operators face no regulatory deadline but the same exposure window. The attribution to MuddyWater is notable: the group typically targets initial access at telecommunications, energy, and government targets across the Middle East, Europe, and North America. CISA on the same day added a directory traversal flaw in Trend Micro $TMICY Apex One on-premise (CVE-2026-34926, CVSS 6.7) to KEV. Both vulnerabilities share the June 4 federal remediation deadline.

Published on
XThreadsFacebookBluesky