TL;DR: A chained vulnerability in Langflow, tracked as CVE-2025-34291 and rated CVSS 9.4, can let a malicious webpage trigger account takeover and remote code execution, exposing workspace tokens and keys that can cascade into downstream cloud and SaaS systems, according to Obsidian Security. The case shows how AI workflow platforms can turn credential concentration into identity blast radius.
At a glance
What this is: This is a vulnerability analysis of Langflow account takeover and remote code execution that shows how a browser-based exploit can expose stored workspace tokens and API keys.
Why it matters: It matters because AI workflow platforms often concentrate NHI credentials, so one compromised session can become a platform-wide and downstream SaaS compromise path.
Context
Langflow is an AI workflow platform that sits between developers, integrations, and the credentials those integrations depend on. In this case, the security problem is not a single weak control but the combination of permissive cross-origin requests, missing CSRF protections, and a code-validation endpoint that can execute attacker-controlled code.
For IAM and NHI teams, the issue is the trust model around refresh tokens, API keys, and workspace-scoped secrets inside a shared workflow surface. When a platform stores multiple downstream credentials in one place, the security question shifts from endpoint hardening to identity blast radius and credential containment.
Obsidian Security’s analysis makes clear that AI workflow systems can turn ordinary web-session weaknesses into broad NHI exposure. That is typical of this class of platform, not an edge case, because their core value comes from connecting many services through one execution plane.
Key questions
Q: What breaks when an AI workflow platform uses cookies for refresh tokens without CSRF protection?
A: The browser becomes an attack delivery channel for authenticated session renewal. If a malicious origin can trigger the refresh flow, the attacker may obtain valid tokens without knowing the user’s password, which turns session management into account takeover exposure. In workflow platforms, that usually means access to downstream integrations as well, not just the platform session.
Q: Why do AI workflow platforms create larger identity blast radius than ordinary SaaS apps?
A: They often store multiple delegated credentials in one place so workflows can call cloud services, databases, and SaaS tools. That concentration means a single compromise can expose far more than the platform itself. The result is a wider blast radius, because the platform is acting as an access broker for many other systems.
A: If the endpoint can execute code or influence runtime behaviour, it should be treated as part of the attack surface, not a passive helper feature. Teams should separate validation from ordinary authenticated workflow actions whenever compromise of that endpoint would let an attacker move from identity abuse to server-side execution.
Q: What should IAM teams review after a browser-based account takeover in an AI workflow platform?
A: Review every credential the platform can refresh, store, or reuse, then check whether those secrets are overprivileged or long-lived. Also confirm whether downstream service accounts, API keys, and tokens can be revoked independently of the platform session. If they cannot, one compromised workspace can become a much broader identity incident.
Technical breakdown
How permissive CORS and missing CSRF combine into account takeover
Langflow’s exploit chain starts with browser-mediated trust. Permissive CORS with credentials allows a malicious origin to interact with authenticated endpoints, while missing CSRF protection on the refresh flow removes the usual check that a request was initiated by the legitimate site. Because the refresh token is accepted in a cross-site context, the attacker can obtain a fresh access token through the victim’s browser session. This is not a theoretical web-hardening issue. It is a session-bound identity failure where browser policy and application logic disagree about who is allowed to refresh a credential.
Practical implication: treat any cookie-based refresh flow in a cross-origin AI platform as a CSRF-sensitive authentication path, not a convenience feature.
Why the code-validation endpoint turns identity abuse into remote code execution
The second stage is code execution by design. Langflow’s validation endpoint evaluates Python snippets to inspect custom components, and before hardening it could be reached without sufficient protection. Once an attacker has valid session material, that endpoint becomes an execution primitive rather than a harmless validation service. The important architectural point is that the platform mixes identity and runtime authority: the same session that authorises workflow editing can also unlock code-paths capable of running server-side instructions. That collapses the boundary between authenticated user action and platform compromise.
Practical implication: isolate code-validation functionality from ordinary authenticated workflow operations and require a separate trust boundary before execution is permitted.
Why stored workspace secrets expand the blast radius
AI workflow platforms often persist tokens, API keys, and other reusable secrets so flows can call external services. That makes compromise durable because the attacker is not just stealing a session, but inheriting the workspace’s integration authority. In Langflow, the analysis shows that exposed secrets can include credentials for cloud and SaaS systems beyond the platform itself. This is the NHI concentration problem: one identity boundary contains many delegated identities, and compromise of the host platform can become delegated compromise everywhere those credentials reach.
Practical implication: inventory every downstream credential stored in the workflow plane and separate execution access from secret custody wherever possible.
Threat narrative
Attacker objective: The attacker aims to turn one browser visit into platform takeover, code execution, and reusable access to connected enterprise systems.
- Entry occurs when a user visits a malicious webpage that can interact with Langflow’s authenticated browser session through permissive cross-origin behaviour.
- Credential access follows when the attacker abuses the refresh flow to obtain fresh access and refresh tokens from the victim’s browser context.
- Escalation occurs when those credentials are used against the code-validation endpoint, turning session access into server-side code execution.
- Impact is full compromise of the Langflow instance and exposure of stored tokens and API keys that can be reused against downstream cloud and SaaS services.
Breaches seen in the wild
- CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
- JADEPUFFER agentic ransomware 2026: The first documented agentic ransomware used harvested keys, default MinIO credentials and a default Nacos signing key to wipe a database.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity blast radius is the core failure mode here: AI workflow platforms can become concentration points for NHI authority, so a single browser-session compromise can expose a credential estate that was never meant to live in one runtime boundary. That changes the governance question from 'is the app authenticated?' to 'how much delegated access sits behind one session?' The practitioner conclusion is that blast radius must be modelled as an identity property, not just a network or application property.
Browser security controls are not sufficient when refresh tokens govern machine access: CSRF and CORS weaknesses matter more in workflow platforms because they do not merely expose a user session, they unlock the credentials that drive automated integrations. This is where conventional web trust assumptions fail NHI governance. The practitioner conclusion is that refresh-token handling deserves the same scrutiny as privileged credential issuance.
Workflow platforms create hidden third-party NHI dependency chains: when a low-code AI platform stores cloud keys, SaaS tokens, and internal service credentials, compromise of the platform becomes indirect compromise of every connected service. That pattern is central to OWASP-NHI concerns around secret leakage, long-lived secrets, and overprivileged NHI. The practitioner conclusion is to govern the platform as an NHI broker, not just an application.
Code execution inside a control plane is a governance boundary breach, not just a vulnerability: once a workflow editor can evaluate code in the same trust domain that holds session credentials, identity and runtime authority become inseparable. That is why AI workflow platforms need stricter separation between editing, validation, and execution. The practitioner conclusion is that approval for workflow change and authority to run code should not share the same path.
Credential concentration creates the same systemic risk across human, NHI, and agentic workflows: the closer a platform gets to being the integration hub for everything else, the more its authentication and secret-handling model determines enterprise exposure. This is exactly where IAM, PAM, and NHI governance converge. The practitioner conclusion is to review any workflow platform as a delegated-access nexus, not a self-contained tool.
What this signals
Identity concentration, not just session weakness, is what makes this class of exploit dangerous: AI workflow platforms increasingly act as delegated-access hubs for cloud and SaaS services. When refresh flows, code execution, and secret storage share one boundary, the platform itself becomes an identity control plane that must be governed like a high-value NHI broker.
Trust boundaries need to move closer to credential issuance: browser session protections matter, but they are not enough when the same session can refresh credentials and unlock workflow execution. Practitioners should assume that any workflow platform handling reusable secrets needs stronger separation between user auth, token refresh, and runtime authority.
Secret persistence is the real enterprise risk multiplier: the issue is not only whether an attacker can take over one account, but whether that account unlocks tokens that persist beyond the session and reach downstream services. That is why platform review should focus on what credentials are stored, how long they live, and whether they can be offboarded cleanly.
For practitioners
- Harden refresh-token handling Move refresh tokens out of cross-site cookie flows where possible, and require explicit CSRF protection whenever SameSite=None is unavoidable for a split frontend and backend.
- Separate validation from execution Treat code-validation endpoints as execution surfaces and place them behind stronger authentication, explicit authorisation checks, and isolated runtime boundaries.
- Inventory downstream credentials Map every API key, database password, and service token stored in the workflow platform so you know what will be exposed if the platform session is compromised.
- Reduce secret persistence in workflows Move high-value secrets to scoped external vaults or service-specific brokers so a platform compromise does not automatically inherit broad downstream access.
- Test cross-origin session paths Review whether authenticated browser requests can refresh or rebind credentials from untrusted origins, especially where cloud and SaaS integrations depend on the session.
Key takeaways
- This Langflow case shows how account takeover becomes much more serious when the platform also stores reusable cloud and SaaS credentials.
- The exploit chain combines browser trust, refresh-token abuse, and code execution, which turns one compromised session into a broader identity incident.
- The control that matters most is separating token refresh, code execution, and secret custody so one weak path does not expose the full workflow estate.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP API Security Top 10 and MITRE ATT&CK define the specific risk controls and attack patterns relevant to this term.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | The article centres on exposed workspace tokens and API keys after platform compromise. |
| NHI-07 — Long-Lived Secrets | Refresh-token reuse and persistent workspace secrets extend the exposure window after takeover. | |
| NHI-05 — Overprivileged NHI | Stored integrations can grant far more downstream access than the workflow actually needs. | |
| Recommendation — Scan workflow platforms for leaked credentials and revoke any secrets exposed through shared sessions. Reduce secret lifetime in workflow platforms and remove long-lived credentials from shared execution planes. Constrain downstream integrations to the minimum authority required for each workflow. | ||
| OWASP API Security Top 10 | API2 — Broken Authentication | The exploit chain abuses authentication and token refresh behaviour across browser and API boundaries. |
| Recommendation — Harden API authentication paths that refresh or reissue tokens from browser contexts. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The attack uses token theft to pivot from platform access into downstream systems. |
| Recommendation — Map token theft and downstream pivot paths to TA0006 and TA0008 in your detections. | ||
Key terms
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Refresh Token: A longer-lived credential that can mint new access tokens without forcing the user to authenticate again. Because refresh tokens can preserve access for extended periods, they are a major governance concern when malicious or over-scoped applications are granted consent.
- Workflow Credential Concentration: The practice of storing multiple service credentials inside a shared workflow platform so automations can call external systems. It simplifies integration but also concentrates delegated authority, which means one platform compromise can expose many downstream identities at once.
- Execution boundary: The point at which an authorised task turns into a real system change, such as writing data, deleting records, spending money, or invoking a downstream tool. In AI governance, controlling the execution boundary matters more than simply approving access, because harm occurs when actions are allowed to complete unchecked.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on May 28, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org