Vulnerability record · CVE-2025-3248 · published 7 April 2025
CVE-2025-3248: Langflow unauthenticated code injection in validate/code endpoint
Langflow · Langflow
Langflow versions prior to 1.3.0 expose the /api/v1/validate/code endpoint without authentication, allowing code injection. A remote attacker can send crafted HTTP requests to execute arbitrary code on the server. This is a critical pre-auth RCE in an AI workflow tool, and it is being exploited in the wild.
Description
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network RCE with CVSS 9.8, KEV listing with known ransomware use, and near-maximum EPSS make this an urgent patch-first issue.
What it is
Langflow versions prior to 1.3.0 expose the /api/v1/validate/code endpoint without authentication, allowing code injection. A remote attacker can send crafted HTTP requests to execute arbitrary code on the server. This is a critical pre-auth RCE in an AI workflow tool, and it is being exploited in the wild.
Impact
An unauthenticated attacker gains remote code execution with the privileges of the Langflow service, leading to full compromise of the host and any data or credentials it can reach. CISA flags known ransomware campaign use, so impact can extend to lateral movement and data destruction.
Attack surface
Reachable over the network via HTTP requests to /api/v1/validate/code; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any internet-exposed or internally reachable Langflow instance below 1.3.0 is a target.
Exploitation
CISA added it to KEV on 2025-05-05 with known ransomware campaign use, and EPSS is 0.9999 (99.98th percentile). A public exploit write-up is referenced, so active exploitation is expected.
What to do
- Upgrade Langflow to 1.3.0 or later immediately; the patch is in PR #6911 and release 1.3.0.
- If upgrade is not possible, remove Langflow from network exposure and restrict access to the service to trusted management networks only.
- Follow CISA KEV required action: apply vendor mitigations, apply BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.
- Rotate any secrets, API keys, and credentials accessible to the Langflow service, and review the host for persistence after suspected exposure.
- Monitor for and block unauthenticated requests to /api/v1/validate/code at the reverse proxy or WAF.
Detection
- Search HTTP access logs for POST or other requests to /api/v1/validate/code, especially from unexpected or external source IPs.
- Look for anomalous child processes spawned by the Langflow service (python, sh, bash, curl, wget) indicating code execution.
- Monitor for outbound connections from Langflow hosts to unfamiliar destinations, consistent with post-exploitation or ransomware staging.
- Audit Langflow instances for version below 1.3.0 and alert on any that remain exposed.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-3248 to the Known Exploited Vulnerabilities catalog on 5 May 2025 as "Langflow Missing Authentication Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 26 May 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/langflow-ai/langflow/pull/6911 | Patch |
| https://github.com/langflow-ai/langflow/releases/tag/1.3.0 | Release Notes |
| https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-a | ExploitThird Party Advisory |
| https://www.vulncheck.com/advisories/langflow-unauthenticated-rce | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3248 | US Government Resource |
Track CVE-2025-3248 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-3248), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.