← Vulnerability feed

Vulnerability record · CVE-2025-3248 · published 7 April 2025

CVE-2025-3248: Langflow unauthenticated code injection in validate/code endpoint

Langflow · Langflow

Langflow versions prior to 1.3.0 expose the /api/v1/validate/code endpoint without authentication, allowing code injection. A remote attacker can send crafted HTTP requests to execute arbitrary code on the server. This is a critical pre-auth RCE in an AI workflow tool, and it is being exploited in the wild.

9.8 CVSS 3.1 Critical CISA KEV since 5 May 2025 Known ransomware use EPSS 100% · top 0.1% CWE-306 · Missing authentication for critical functionCWE-94 · Code injection
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 1 tagged exploit
14 Jul 2026Last modified by NVD

Description

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network RCE with CVSS 9.8, KEV listing with known ransomware use, and near-maximum EPSS make this an urgent patch-first issue.

What it is

Langflow versions prior to 1.3.0 expose the /api/v1/validate/code endpoint without authentication, allowing code injection. A remote attacker can send crafted HTTP requests to execute arbitrary code on the server. This is a critical pre-auth RCE in an AI workflow tool, and it is being exploited in the wild.

Impact

An unauthenticated attacker gains remote code execution with the privileges of the Langflow service, leading to full compromise of the host and any data or credentials it can reach. CISA flags known ransomware campaign use, so impact can extend to lateral movement and data destruction.

Attack surface

Reachable over the network via HTTP requests to /api/v1/validate/code; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any internet-exposed or internally reachable Langflow instance below 1.3.0 is a target.

Exploitation

CISA added it to KEV on 2025-05-05 with known ransomware campaign use, and EPSS is 0.9999 (99.98th percentile). A public exploit write-up is referenced, so active exploitation is expected.

What to do

  • Upgrade Langflow to 1.3.0 or later immediately; the patch is in PR #6911 and release 1.3.0.
  • If upgrade is not possible, remove Langflow from network exposure and restrict access to the service to trusted management networks only.
  • Follow CISA KEV required action: apply vendor mitigations, apply BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.
  • Rotate any secrets, API keys, and credentials accessible to the Langflow service, and review the host for persistence after suspected exposure.
  • Monitor for and block unauthenticated requests to /api/v1/validate/code at the reverse proxy or WAF.

Detection

  • Search HTTP access logs for POST or other requests to /api/v1/validate/code, especially from unexpected or external source IPs.
  • Look for anomalous child processes spawned by the Langflow service (python, sh, bash, curl, wget) indicating code execution.
  • Monitor for outbound connections from Langflow hosts to unfamiliar destinations, consistent with post-exploitation or ransomware staging.
  • Audit Langflow instances for version below 1.3.0 and alert on any that remain exposed.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-3248 to the Known Exploited Vulnerabilities catalog on 5 May 2025 as "Langflow Missing Authentication Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 26 May 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-3248 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-9198Langflow auto_login and code validation chain enables unauthenticated RCEIBM Langflow OSS 1.0.0 through 1.10.0 exposes /api/v1/auto_login, which mints SUPERUSER tokens to any network caller, and /api/v1/validate/code, whic…KEVEPSS 29%analysed9.8CVE-2026-0770Langflow validate endpoint exec_globals remote code executionLangflow mishandles the exec_globals parameter passed to its validate endpoint, allowing functionality from an untrusted control sphere to be include…KEVEPSS 64%analysed9.4CVE-2025-34291Langflow CORS misconfiguration leads to token theft and RCELangflow up to and including 1.6.9 ships an overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) and a refresh token …KEVEPSS 93%analysed9.3CVE-2026-33017Langflow build_public_tmp endpoint unauthenticated remote code executionLangflow versions prior to 1.9.0 expose the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint without authentication, and when the optional data …KEVEPSS 25%analysed8.4CVE-2026-55255Langflow IDOR in responses endpoint allows cross-user flow executionLangflow before 1.9.1 has an insecure direct object reference in the /api/v1/responses endpoint. An authenticated attacker can supply another user's …KEVEPSS 0.89%analysed10.0CVE-2026-10134Langflow code injection vulnerabilityIBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversat…EPSS 0.64%10.0CVE-2026-10561Langflow code injection vulnerabilityIBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass tha…EPSS 1.0%9.9CVE-2026-19295Langflow vulnerabilityIBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving…EPSS 3.3%

Source: NIST National Vulnerability Database (record CVE-2025-3248), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.