CVE-2025-3248

critical

Description

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

References

https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-prioritize-patching-langflow-auth-bypass-flaw/

https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html

https://www.infosecurity-magazine.com/news/researchers-first-agentic/

https://www.hipaajournal.com/ai-agent-conducts-first-fully-autonomous-ransomware-attack/

https://www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack

https://cyberscoop.com/sysdig-judepuffer-ai-agentic-ransomware-attack/

https://www.bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack/

https://www.securityweek.com/agentic-ai-used-to-conduct-ransomware-attack-via-langflow/

https://thehackernews.com/2026/07/new-avalon-malware-framework-packs.html

https://www.theregister.com/security/2026/07/02/smooth-ai-criminal-drives-first-end-to-end-agentic-ransomware-attack/5266073

https://thehackernews.com/2026/07/ai-agent-exploits-langflow-rce-to.html

https://hackread.com/sysdig-jadepuffer-first-agentic-ransomware-operation/

https://webflow.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion

https://thehackernews.com/2026/06/langflow-rce-exploited-to-deploy-monero.html

https://www.bleepingcomputer.com/news/security/path-traversal-flaw-in-ai-dev-platform-langflow-exploited-in-attacks/

https://intezer.com/blog/how-attackers-access-llm-inference/

https://www.helpnetsecurity.com/2026/03/27/cve-2026-33017-cve-2026-33634-exploited/

https://thehackernews.com/2026/03/langchain-langgraph-flaws-expose-files.html

https://www.darkreading.com/vulnerabilities-threats/critical-flaw-langflow-ai-platform-under-attack

https://www.bleepingcomputer.com/news/security/cisa-new-langflow-flaw-actively-exploited-to-hijack-ai-workflows/

https://securityaffairs.com/190018/security/u-s-cisa-adds-a-langflow-flaw-to-its-known-exploited-vulnerabilities-catalog.html

https://thehackernews.com/2026/03/critical-langflow-flaw-cve-2026-33017.html

https://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours

https://securelist.com/vulnerabilities-and-exploits-in-q2-2025/117333/

https://www.darkreading.com/remote-workforce/threat-actors-leaning-genai-tools

https://hackread.com/langflow-vulnerability-cve-2025-3248-actively-exploited-cisa/

https://www.securityweek.com/critical-vulnerability-in-ai-builder-langflow-under-attack/

https://www.cisa.gov/news-events/alerts/2025/05/05/cisa-adds-one-known-exploited-vulnerability-catalog

https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/

Details

Source: Mitre, NVD

Published: 2025-04-07

Updated: 2026-07-14

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

CVSS v4

Base Score: 9.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: Critical

EPSS

EPSS: 0.9999