PT-2025-15232 · Langflow · Langflow
Naveen Sunkavally
·
Published
2025-04-07
·
Updated
2025-07-17
·
CVE-2025-3248
10
Critical
Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
## Vulnerability Report
**Name of the Vulnerable Software and Affected Versions:** Langflow versions prior to 1.3.0
**Description:**
Langflow is susceptible to a critical remote code execution (RCE) vulnerability (CVE-2025-3248) due to a missing authentication check in the `/api/v1/validate/code` endpoint. This allows unauthenticated attackers to send crafted HTTP requests to execute arbitrary code on the system. The Flodrix botnet is actively exploiting this vulnerability to deploy malware, including reconnaissance and DDoS attacks. Approximately 663 servers are currently exposed. The vulnerability allows for full system compromise, data theft, and potential use in DDoS attacks.
**Recommendations:**
Upgrade Langflow to version 1.3.0 or later to address this vulnerability. Restrict network access to Langflow instances to mitigate the risk.
Exploit
Fix
RCE
Code Injection
Missing Authentication
Related Identifiers
Affected Products
References · 297
- 🔥 https://github.com/ynsmroztas/CVE-2025-3248-Langflow-RCE⭐ 12 🔗 3 · Exploit
- 🔥 https://github.com/verylazytech/CVE-2025-3248⭐ 9 🔗 1 · Exploit
- 🔥 https://github.com/PuddinCat/CVE-2025-3248-POC⭐ 1 · Exploit
- 🔥 https://horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai · Exploit
- https://github.com/langflow-ai/langflow/pull/6911⭐ 74369 🔗 6828 · Patch
- https://osv.dev/vulnerability/PYSEC-2025-36 · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-06683 · Security Note
- https://safe-surf.ru/specialists/bulletins-nkcki/720585 · Security Note
- https://osv.dev/vulnerability/GHSA-rvqx-wpfh-mfx7 · Vendor Advisory
- https://osv.dev/vulnerability/GHSA-c995-4fw3-j39m · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-3248 · Security Note
- https://osv.dev/vulnerability/CVE-2025-3248 · Vendor Advisory
- https://github.com/langflow-ai/langflow⭐ 75068 🔗 6845 · Note
- https://github.com/langflow-ai/langflow/commit/faac4db133de32fcb6d483fa9ff52f40ce42bdc0⭐ 75068 🔗 6845 · Note
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-rvqx-wpfh-mfx7⭐ 75068 🔗 6845 · Note