CRITICAL
CVE-2025-3248
CVSS
9.8
KEV
Description
Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary
code.
Summary dbcve.org
Langflow versions before 1.3.0 contain a code injection vulnerability in the /api/v1/validate/code API endpoint that allows unauthenticated remote attackers to execute arbitrary code via crafted HTTP requests.
Mitigation
Upgrade Langflow to version 1.3.0 or later to remediate the code injection vulnerability.
Weakness (CWE)
CWE-306
Missing Authentication
CWE-94
Code Injection
EPSS Score
99.99%
Probability of exploitation in next 30 days
100th percentile
References
https://github.com/langflow-ai/langflow/pull/6911
Patch
https://github.com/langflow-ai/langflow/releases/tag/1.3.0
Release Notes
https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/
Exploit, Third Party Advisory
https://www.vulncheck.com/advisories/langflow-unauthenticated-rce
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3248
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.