CRITICAL

CVE-2025-3248

Langflow Langflow 2025-04-07 CVSS v3.1
CVSS
9.8
KEV

Description

Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary
code.

Summary dbcve.org

Langflow versions before 1.3.0 contain a code injection vulnerability in the /api/v1/validate/code API endpoint that allows unauthenticated remote attackers to execute arbitrary code via crafted HTTP requests.

Mitigation

Upgrade Langflow to version 1.3.0 or later to remediate the code injection vulnerability.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-306 Missing Authentication
CWE-94 Code Injection

EPSS Score

99.99%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE