← back
CVE-2025-3248

Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code

CVSS 9.8 CRITICALEPSS 100.0%● KEVCWE-306
In short

Langflow versions before 1.3.0 allow anyone on the internet to run malicious code on the server without logging in, by sending specially crafted requests to a code validation endpoint. This is critical because attackers can take complete control of the affected system.

Technical detail

An unauthenticated remote attacker can exploit code injection in the /api/v1/validate/code endpoint to achieve arbitrary code execution on the server. The vulnerability exists due to insufficient input validation in code validation logic, requiring only network access to the vulnerable endpoint; successful exploitation grants full system compromise.

Summary generated and translated by AI from the official description.
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
langflow-ai · langflow
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →