CVE-2025-3248
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
Description
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
In plain language
AI Act nowLangflow versions before 1.3.0 allow an unauthenticated attacker to run arbitrary code over the internet via /api/v1/validate/code, so most small businesses should treat this as an urgent fix.
Unauthenticated RCE in Langflow via the /api/v1/validate/code endpoint (code validation accepts attacker-controlled input that can lead to arbitrary code execution); this is confirmed in the CISA KEV catalog and is fixed in langflow 1.3.0 (and langflow-base 0.3.0).
What to do now
- Check whether you run Langflow and what version you have installed (including any langflow-base dependency).
- If your Langflow version is earlier than 1.3.0, plan an immediate upgrade to Langflow 1.3.0.
- If you use/ship langflow-base, upgrade langflow-base to 0.3.0 or later.
- If you cannot upgrade right away, restrict network access so the /api/v1/validate/code endpoint is not reachable from the public internet, and follow your vendor’s mitigation guidance until upgrades are completed.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- CISA orders urgent action on actively exploited Langflow RCE flawen-us·BleepingComputer· Exploited Langflow ai-ml
- JadePuffer returns with ransomware built to target AI models and infrastructureen-us·Help Net Security· Exploited Langflow JadePuffer
- New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attacken·The Hacker News· Exploited Langflow JADEPUFFER
- JadePuffer agentic attacks now target AI model data with ransomwareen-us·BleepingComputer· Incident JadePuffer ai-ml
- 13th July – Threat Intelligence Reporten-us·Check Point Research· Advisory AssuranceAmerica data-breach
- Вымогатель JadePuffer использовал ИИ-агента для автоматизации атакиru-ru·Хакер (xakep.ru)· Exploited Langflow ransomware
- CISA orders feds to prioritize patching Langflow auth bypass flawen-us·BleepingComputer· Exploited Langflow ai-ml
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEVen·The Hacker News· Exploited Adobe ColdFusion web-app
- Первая полностью автономная атака AI-агента: что произошло и как защититьсяru·Хабр — Информационная безопасность· Incident Langflow ai-ml
- JadePuffer: The First Complete LLM-Driven Ransomware Attacken·Dark Reading· Exploited ransomware
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-3248 and every CVE in our database. Create a free account — no credit card required.
Create Free Account