CVE-2025-3248criticalunder attackransomwareCWE-306

CVE-2025-3248: critical vulnerability in langflow-ai langflow

Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 100%
from disclosure to weapon3 days
Published on NVDApr 7
1st PoC+3d
metasploit+2d
CISA KEV+28d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
62 public exploit(s)
Action required by CISAfederal deadline: 2025-05-26

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

Langflow versions before 1.3.0 allow anyone on the internet to run malicious code on the server without logging in, by sending specially crafted requests to a code validation endpoint. This is critical because attackers can take complete control of the affected system.

Technical detail

An unauthenticated remote attacker can exploit code injection in the /api/v1/validate/code endpoint to achieve arbitrary code execution on the server. The vulnerability exists due to insufficient input validation in code validation logic, requiring only network access to the vulnerable endpoint; successful exploitation grants full system compromise.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
langflow-ai · langflow
public PoCs found — 62
exploitdbwww.exploit-db.com/exploits/52262unverifiedexploitdbwww.exploit-db.com/exploits/52364unverifiedgithubgithub.com/ynsmroztas/CVE-2025-3248-Langflow-RCE★ 17githubgithub.com/xuemian168/CVE-2025-3248★ 11githubgithub.com/verylazytech/CVE-2025-3248★ 10githubgithub.com/0-d3y/langflow-rce-exploit★ 7githubgithub.com/dennisec/Mass-CVE-2025-3248★ 3githubgithub.com/EQSTLab/CVE-2025-3248★ 3githubgithub.com/drackyjr/cve-2025-3248-exploit★ 3githubgithub.com/hideki233/CVE-2025-3248-Langflow-RCE★ 3githubgithub.com/PuddinCat/CVE-2025-3248-POC★ 3githubgithub.com/Kiraly07/Demo_CVE-2025-3248★ 2githubgithub.com/zapstiko/CVE-2025-3248★ 2githubgithub.com/imbas007/CVE-2025-3248★ 2githubgithub.com/vigilante-1337/CVE-2025-3248★ 2githubgithub.com/b0ySie7e/CVE-2025-3248-POC★ 1githubgithub.com/zoly-zoly/CVE-2025-3248★ 1githubgithub.com/r0otk3r/CVE-2025-3248★ 1githubgithub.com/Vip3rLi0n/CVE-2025-3248★ 1githubgithub.com/tiemio/RCE-CVE-2025-3248★ 1githubgithub.com/Praison001/CVE-2025-3248★ 1githubgithub.com/preemware/langflow-exploit★ 1githubgithub.com/bambooqj/cve-2025-3248★ 1githubgithub.com/GraySignal/CVE-2025-3248★ 1githubgithub.com/LeotheGGman/Langflow-RCE-CVE-2025-3248★ 0githubgithub.com/nebari-playground/langflow-cve-2025-3248★ 0githubgithub.com/Atomics-hub/exposecheck★ 0githubgithub.com/dennisec/CVE-2025-3248★ 0githubgithub.com/ill-deed/Langflow-CVE-2025-3248-Multi-target★ 0githubgithub.com/min8282/CVE-2025-3248★ 0githubgithub.com/wand3rlust/CVE-2025-3248★ 0githubgithub.com/12-test-12/CVE-2025-3248★ 0githubgithub.com/0xgh057r3c0n/CVE-2025-3248★ 0vulncheckvulncheck.com/xdb/25e094423db0unverifiedvulncheckvulncheck.com/xdb/c8205b76d58bunverifiedvulncheckvulncheck.com/xdb/684115e325dbunverifiedvulncheckvulncheck.com/xdb/fe2de4ea8e83unverifiedvulncheckvulncheck.com/xdb/68b57b9315a2unverifiedvulncheckvulncheck.com/xdb/ee9c80f0dd42unverifiedvulncheckvulncheck.com/xdb/e7c172788c42unverifiedvulncheckvulncheck.com/xdb/8ae92c1bc671unverifiedvulncheckvulncheck.com/xdb/631b46774fd7unverifiedvulncheckvulncheck.com/xdb/5bba2deca1c3unverifiedvulncheckvulncheck.com/xdb/dbf02ebce5d9unverifiedvulncheckvulncheck.com/xdb/e3068430fa4dunverifiedvulncheckvulncheck.com/xdb/ad786ecce441unverifiedvulncheckvulncheck.com/xdb/36d353279df8unverifiedvulncheckvulncheck.com/xdb/145490c5ce6funverifiedvulncheckvulncheck.com/xdb/be18e792efe8unverifiedvulncheckvulncheck.com/xdb/93417d485096unverifiedvulncheckvulncheck.com/xdb/f4d3bcf9f10funverifiedvulncheckvulncheck.com/xdb/2098ab2f7185unverifiedvulncheckvulncheck.com/xdb/288fea3e2ebfunverifiedvulncheckvulncheck.com/xdb/cd6d4cd25599unverifiedvulncheckvulncheck.com/xdb/1b00d10ad09eunverifiedcve_referencewww.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/unverifiedvulncheckvulncheck.com/xdb/58f291eee1deunverifiedvulncheckvulncheck.com/xdb/efad80d04720unverifiedvulncheckvulncheck.com/xdb/3e9d384f80eeunverifiedvulncheckvulncheck.com/xdb/a72c4ca01c3dunverifiedvulncheckvulncheck.com/xdb/05d95ecf10d9unverifiedvulncheckvulncheck.com/xdb/bc487190c5b1unverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.