Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
https://www.securityweek.com/hackers-start-exploiting-critical-langflow-vulnerability/
https://www.databreachtoday.com/attacks-targeting-langflow-ai-agent-building-tool-surge-a-32712
https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html
https://www.vulncheck.com/blog/pwning-the-ai-stack
https://latesthackingnews.com/2026/07/26/encforge-ransomware-langflow-ai-models/
https://www.helpnetsecurity.com/2026/07/21/jadepuffer-encforge-ransomware/
https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html
https://www.infosecurity-magazine.com/news/jadepuffer-ai-model-ransomware/
https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html
https://www.infosecurity-magazine.com/news/researchers-first-agentic/
https://www.hipaajournal.com/ai-agent-conducts-first-fully-autonomous-ransomware-attack/
https://cyberscoop.com/sysdig-judepuffer-ai-agentic-ransomware-attack/
https://www.securityweek.com/agentic-ai-used-to-conduct-ransomware-attack-via-langflow/
https://thehackernews.com/2026/07/new-avalon-malware-framework-packs.html
https://thehackernews.com/2026/07/ai-agent-exploits-langflow-rce-to.html
https://hackread.com/sysdig-jadepuffer-first-agentic-ransomware-operation/
https://webflow.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion
https://thehackernews.com/2026/06/langflow-rce-exploited-to-deploy-monero.html
https://intezer.com/blog/how-attackers-access-llm-inference/
https://www.helpnetsecurity.com/2026/03/27/cve-2026-33017-cve-2026-33634-exploited/
https://thehackernews.com/2026/03/langchain-langgraph-flaws-expose-files.html
https://www.darkreading.com/vulnerabilities-threats/critical-flaw-langflow-ai-platform-under-attack
https://thehackernews.com/2026/03/critical-langflow-flaw-cve-2026-33017.html
https://securelist.com/vulnerabilities-and-exploits-in-q2-2025/117333/
https://www.darkreading.com/remote-workforce/threat-actors-leaning-genai-tools
https://hackread.com/langflow-vulnerability-cve-2025-3248-actively-exploited-cisa/
https://www.securityweek.com/critical-vulnerability-in-ai-builder-langflow-under-attack/
https://github.com/joaovicdev/EXPLOIT-CVE-2026-9198
https://github.com/HaakimSec/zero2shell-50
https://github.com/Atomics-hub/exposecheck
https://github.com/diedromeo/CVE-Labs-2025-2026
https://github.com/elaz48/langdoctor
https://github.com/allannjuguna/Exploit-Development
https://github.com/HORKimhab/poc-cve-collection
https://github.com/1392081456/sigma-detection-rules
https://github.com/bndxn/cve-awareness
https://github.com/get-xor/coreweave-demo-2026-05
https://github.com/MaxMnMl/langflow-CVE-2026-33017-poc
https://github.com/nebari-playground/langflow-cve-2025-3248
https://github.com/EvanThomasLuke/HACK-AGI-CONTAINERS
https://github.com/b0ySie7e/CVE-2025-3248-POC
https://github.com/drackyjr/cve-2025-3248-exploit
https://github.com/verylazytech/CVE-2025-64446
https://github.com/bambooqj/cve-2025-3248
https://github.com/star5o/AutoPoC
https://github.com/galgantar/langflow-cve
https://github.com/r0otk3r/CVE-2025-3248
https://github.com/dennisec/Mass-CVE-2025-3248
https://github.com/dennisec/CVE-2025-3248
https://github.com/0-d3y/langflow-rce-exploit
https://github.com/issamjr/CVE-2025-3248-Scanner
https://github.com/B1ack4sh/Blackash-CVE-2025-3248
https://github.com/zapstiko/CVE-2025-3248
https://github.com/imbas007/CVE-2025-3248
https://github.com/ynsmroztas/CVE-2025-3248-Langflow-RCE
https://github.com/tiemio/RCE-CVE-2025-3248
https://github.com/Vip3rLi0n/CVE-2025-3248
https://github.com/vigilante-1337/CVE-2025-3248
https://github.com/PuddinCat/GithubRepoSpider
https://github.com/Praison001/CVE-2025-3248
https://github.com/heqnx/cve-poc-mon
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3248
Published: 2025-04-07
Updated: 2026-07-14
Known Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
Base Score: 9.3
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: Critical
EPSS: 0.99996