CVE-2025-3248
Langflow Missing Authentication Vulnerability - [Actively Exploited]
Description
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
INFO
Published Date :
April 7, 2025, 3:15 p.m.
Last Modified :
July 14, 2026, 11:17 p.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CISA KEV (Known Exploited Vulnerabilities)
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.
Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Known Detected Jul 08, 2026
This vulnerability affects a common open-source project, third-party library, or a protocol used by different products. For more information, please see: https://github.com/advisories/GHSA-c995-4fw3-j39m ; https://nvd.nist.gov/vuln/detail/CVE-2025-3248
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | CRITICAL | [email protected] | ||||
| CVSS 3.1 | CRITICAL | [email protected] |
Solution
- Update Langflow to version 1.3.0 or later.
Public PoC/Exploit Available at Github
CVE-2025-3248 has a 192 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2025-3248.
| URL | Resource |
|---|---|
| https://github.com/langflow-ai/langflow/pull/6911 | Patch |
| https://github.com/langflow-ai/langflow/releases/tag/1.3.0 | Release Notes |
| https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/ | Exploit Third Party Advisory |
| https://www.vulncheck.com/advisories/langflow-unauthenticated-rce | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3248 | US Government Resource |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2025-3248 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2025-3248
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Security audit skill for LLM agents - prompt injection scanner, attack catalog & defense checklist
agent-skills ai-security cyber-security cybersecurity llm-security prompt-injection red-team
Python
Zero2Shell-50: 50 containerized Remote Code Execution labs covering critical CVEs from 2014-2026. Each lab includes vulnerable Docker environments, working exploits, root cause analysis, and mitigation guides. Covers Java, Python, PHP, JavaScript, and shell-based vulnerabilities.
Dockerfile PHP Python Java Shell JavaScript
Defensive single-target self-check for Langflow CVE-2025-3248 exposure
JavaScript HTML
Educational, Dockerized reproductions of publicly disclosed 2025-2026 CVEs: root-cause analysis, attack flows, PoCs, detections, and patch analysis.
cve cybersecurity detection-engineering docker mitre-attack patch-diff poc security-research vulnerability-research
Makefile Dockerfile JavaScript Mermaid Python Shell Erlang HTML
Offensive Security Engineer · Threat Intelligence Researcher · CTF Author — GitHub profile.
offensive-security security application-security bug-bounty cve-research penetration-testing ctf-author ctf-developer cve-researcher ai-security llm-security
None
Python Shell PHP TypeScript JavaScript HCL PowerShell C
LangChain 入门实战Demo从初级到高级,基于DeepSeek大模型实现Agent工具调用,了解LangChain核心知识点,助力AI开发
Python
A one-page hardening checklist built from JADEPUFFER, the first fully autonomous LLM-run ransomware attack. Free to fork.
whs4기 가상화(컨테이너 보안 실무) 과제
Python Shell Dockerfile
A free, machine-readable feed of notable open-source dependency CVEs ranked by live EPSS exploit-probability (FIRST.org, daily). Pure-stdlib Python.
cve cvss dependency-scanning epss first-org osv security supply-chain-security vulnerability vulnerability-management
Python
Production-readiness and security scanner for LangGraph/LangChain projects. Catches known CVEs, insecure checkpointer configs, and footguns before they ship. Zero API key, fully offline.
ai-agents cli devsecops langchain langflow langgraph llm-security python sast security static-analysis supply-chain-security vulnerability-scanner
Python HTML
Daily tech-watch digest (AI, dev, DevOps, data, cloud). Auto-published from my watch on baptisteblouin.fr
ai artificial-intelligence automation cloud cloudflare-workers data-engineering devops digest github-actions llm machine-learning mlops newsletter rss tech-news tech-watch ai-news
JavaScript
webwiki
252 standalone, live-validated CVE exploit PoCs (pure-Python stdlib) across web apps, AI/ML platforms and the Linux kernel; 75 in the CISA KEV catalog. For authorized security testing and education.
cve exploit penetration-testing poc security-research vulnerability cybersecurity ethical-hacking infosec rce red-team security appsec cisa-kev deserialization exploit-development proof-of-concept python
Python C
A collection of CVE research, patch diff analysis, reverse engineering , exploit development notes, and PoCs
HTML Python
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2025-3248 vulnerability anywhere in the article.
-
Trend Micro
The Signs Were There: What the First Autonomous Ransomware Case Confirms
Cyber Threats An AI agent has run a ransomware intrusion on its own for the first time, from break-in to data destruction. The autonomous attacks TrendAI™ Research predicted are beginning to arrive, ... Read more
-
The Hacker News
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted ... Read more
-
Krypt3ia
Threat Intelligence Report: JADEPUFFER Agentic Ransomware and Automated Extortion
Report date: July 13, 2026Threat type: Agentic ransomware, destructive extortion, cloud and application compromiseActivity status: EmergingAttribution: UnattributedConfidence: ModeratePrimary source: ... Read more
-
The Hacker News
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The ... Read more
-
TheCyberThrone
JadePuffer: The Dawn of Agentic AI Ransomware
When Artificial Intelligence Stops Assisting Attackers and Starts Becoming the AttackerCybersecurity has long anticipated the day when Artificial Intelligence would transition from being a supporting ... Read more
-
The Hacker News
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by means of a multi-stage phishing chain capable of bypassing traditio ... Read more
-
The Hacker News
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research Team calls the operator JADEPUFFER and says a large ... Read more
-
The Hacker News
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026- ... Read more
-
TheCyberThrone
CISA adds Langflow and Trivy bugs to KEV Catalog
Langflow Code Injection Flaw Actively Exploited — CVE-2026-33017CISA has added a critical code injection vulnerability in Langflow to its Known Exploited Vulnerabilities catalog, confirming active exp ... Read more
-
The Hacker News
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure
A critical security flaw impacting Langflow has come under active exploitation within 20 hours of public disclosure, highlighting the speed at which threat actors weaponize newly published vulnerabili ... Read more
-
Daily CyberSecurity
High-Severity RCE Flaw in Atlassian Bamboo Threatens CI/CD Environments
Atlassian has sounded the alarm for users of its Bamboo Data Center, uncovering a high-severity Remote Code Execution (RCE) vulnerability that could allow attackers to seize control of development env ... Read more
-
Help Net Security
Agentic attack chains advance as infostealers flood criminal markets
Cybercriminals spent much of 2025 automating their operations, shifting from one-off attacks to systems that can run entire intrusion cycles with minimal human input. Data collected from criminal foru ... Read more
-
CybersecurityNews
Top 10 High-Risk Vulnerabilities Of 2025 that Exploited in the Wild
The cybersecurity landscape in 2025 has been marked by an unprecedented surge in critical vulnerabilities, with over 21,500 CVEs disclosed in the first half of the year alone, representing a 16-18% in ... Read more
-
Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
UK and US Blame Three Chinese Tech Firms for Global Cyberattacks
A coalition of international cybersecurity agencies led by the UK’s National Cyber Security Centre (NCSC) has publicly linked three China-based technology companies to a long-running global cyberattac ... Read more
-
Daily CyberSecurity
Langflow Hit by Privilege Escalation Flaw: CVE-2025-57760
Log into UI as new superuser The Langflow project has issued an important security advisory regarding a newly discovered vulnerability that poses a severe risk to organizations deploying AI-powered wo ... Read more
-
Cyber Security News
Hackers Exploiting Critical Langflow Vulnerability to Deploy Flodrix Botnet and Take System Control
Langflow, the popular Python framework for rapid AI prototyping, is under siege after researchers disclosed CVE-2025-3248, a flaw in the /api/v1/validate/code endpoint that lets unauthenticated attack ... Read more
-
Dark Reading
Hackers Exploit Critical Langflow Flaw to Unleash Flodrix Botnet
Source: BeeBright via ShutterstockAttackers are actively targeting a critical flaw in a popular Python-based Web app for building AI agents and workflows to unleash a powerful botnet that can cause fu ... Read more
-
The Hacker News
New Flodrix Botnet Variant Exploits Langflow AI Server RCE Bug to Launch DDoS Attacks
Cybersecurity researchers have called attention to a new campaign that's actively exploiting a recently disclosed critical security flaw in Langflow to deliver the Flodrix botnet malware. "Attackers u ... Read more
-
Cyber Security News
Hackers Actively Exploiting Langflow RCE Vulnerability to Deploy Flodrix Botnet
Security researchers have uncovered an active cyberattack campaign targeting Langflow servers through CVE-2025-3248, a critical remote code execution vulnerability that allows threat actors to deploy ... Read more
-
Trend Micro
Critical Langflow Vulnerability (CVE-2025-3248) Actively Exploited to Deliver Flodrix Botnet
Summary: Trend™ Research has identified an active campaign exploiting CVE-2025-3248 to deliver the Flodrix botnet. Attackers use the vulnerability to execute downloader scripts on compromised Langflow ... Read more
The following table lists the changes that have been made to the
CVE-2025-3248 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by [email protected]
Jul. 14, 2026
Action Type Old Value New Value Changed Affected [{'repo': 'https://github.com/langflow-ai/langflow', 'vendor': 'langflow-ai', 'product': 'langflow', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '1.3.0', 'versionType': 'semver'}], 'defaultStatus': 'unaffected'}] [{'repo': 'https://github.com/langflow-ai/langflow', 'vendor': 'langflow-ai', 'product': 'langflow', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '1.3.0', 'versionType': 'semver'}], 'packageURL': 'pkg:github/langflow-ai/langflow', 'defaultStatus': 'unaffected'}] -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2025-3248', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-08-15T19:50:13.871465Z'} -
CVE Modified by [email protected]
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://github.com/langflow-ai/langflow', 'vendor': 'langflow-ai', 'product': 'langflow', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '1.3.0', 'versionType': 'semver'}], 'defaultStatus': 'unaffected'}] -
Modified Analysis by [email protected]
Nov. 06, 2025
Action Type Old Value New Value Added Reference Type VulnCheck: https://www.vulncheck.com/advisories/langflow-unauthenticated-rce Types: Third Party Advisory -
CVE Modified by [email protected]
Nov. 04, 2025
Action Type Old Value New Value Added Reference https://www.vulncheck.com/advisories/langflow-unauthenticated-rce -
Modified Analysis by [email protected]
Oct. 31, 2025
Action Type Old Value New Value Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3248 Types: US Government Resource -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Oct. 21, 2025
Action Type Old Value New Value Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3248 -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Oct. 21, 2025
Action Type Old Value New Value Removed Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3248 -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Oct. 21, 2025
Action Type Old Value New Value Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3248 -
Initial Analysis by [email protected]
May. 07, 2025
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Added CWE CWE-94 Added CWE CWE-306 Added CPE Configuration OR *cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* versions up to (excluding) 1.3.0 Added Reference Type VulnCheck: https://github.com/langflow-ai/langflow/pull/6911 Types: Patch Added Reference Type VulnCheck: https://github.com/langflow-ai/langflow/releases/tag/1.3.0 Types: Release Notes Added Reference Type VulnCheck: https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/ Types: Exploit, Third Party Advisory -
CVE CISA KEV Update by 9119a7d8-5eab-497f-8521-727c672e3725
May. 06, 2025
Action Type Old Value New Value Added Date Added 2025-05-05 Added Due Date 2025-05-26 Added Required Action Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Added Vulnerability Name Langflow Missing Authentication Vulnerability -
CVE Modified by [email protected]
Apr. 09, 2025
Action Type Old Value New Value Added Reference https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/ -
New CVE Received by [email protected]
Apr. 07, 2025
Action Type Old Value New Value Added Description Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code. Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Added CWE CWE-306 Added Reference https://github.com/langflow-ai/langflow/pull/6911 Added Reference https://github.com/langflow-ai/langflow/releases/tag/1.3.0