Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html
https://www.infosecurity-magazine.com/news/researchers-first-agentic/
https://www.hipaajournal.com/ai-agent-conducts-first-fully-autonomous-ransomware-attack/
https://cyberscoop.com/sysdig-judepuffer-ai-agentic-ransomware-attack/
https://www.securityweek.com/agentic-ai-used-to-conduct-ransomware-attack-via-langflow/
https://thehackernews.com/2026/07/new-avalon-malware-framework-packs.html
https://thehackernews.com/2026/07/ai-agent-exploits-langflow-rce-to.html
https://hackread.com/sysdig-jadepuffer-first-agentic-ransomware-operation/
https://webflow.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion
https://thehackernews.com/2026/06/langflow-rce-exploited-to-deploy-monero.html
https://intezer.com/blog/how-attackers-access-llm-inference/
https://www.helpnetsecurity.com/2026/03/27/cve-2026-33017-cve-2026-33634-exploited/
https://thehackernews.com/2026/03/langchain-langgraph-flaws-expose-files.html
https://www.darkreading.com/vulnerabilities-threats/critical-flaw-langflow-ai-platform-under-attack
https://thehackernews.com/2026/03/critical-langflow-flaw-cve-2026-33017.html
https://securelist.com/vulnerabilities-and-exploits-in-q2-2025/117333/
https://www.darkreading.com/remote-workforce/threat-actors-leaning-genai-tools
https://hackread.com/langflow-vulnerability-cve-2025-3248-actively-exploited-cisa/
https://www.securityweek.com/critical-vulnerability-in-ai-builder-langflow-under-attack/
Published: 2025-04-07
Updated: 2026-07-14
Known Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
Base Score: 9.3
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: Critical
EPSS: 0.9999