CVE-2025-3248
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
- Published Apr 7, 2025
- CVSS 9.8 critical
- 100.0% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A Metasploit module exploits it
- A fix is available
Affected software
In the news
- The vulnerabilities AI finds are the ones attackers want Help Net Security ·
- Vulnerability Discovery and Exploitation Trends in the AI Era Google Threat Intelligence ·
- JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources The Hacker News ·
- Same Target, Different Playbooks: Two Attackers, Two Different Paths to Pwning the AI Stack VulnCheck Blog ·