CVE-2025-3248
KEV · ransomware Critical · CVSS 9.8Langflow — Unauthenticated Remote Code Execution via Python code injection (exec)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- Listed
- ransomware
- Class
- oss containerizable
- CWE-306, CWE-94, CWE-306
Description
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
Search profile — drives PoC discovery
Symbols /api/v1/validate/codeexecvalidate_codelangflowlangflow-basecode injection
Keywords CVE-2025-3248Langflow RCELangflow code injectionlangflow validate code endpointlangflow unauthenticated RCElangflow /api/v1/validate/code exploitlangflow exec RCE PoClangflow 1.3.0 vulnerability
Versions: < 1.3.0
Ranked PoCs (80) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 0
- ★ 0
- ★ 2
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 9
- ★ 2
- ★ 1
- ★ 0
- ★ 17
- ★ 10
- ★ 7
- ★ 3
- ★ 2
- ★ 1
- ★ 1
- ★ 1
- ★ 1
- ★ 0
- ★ 3drackyjr/cve-2025-3248-exploit needs reviewgh_search · Python
- ★ 2EQSTLab/CVE-2025-3248 needs reviewgh_search · Python
- ★ 1b0ySie7e/CVE-2025-3248-POC needs reviewgh_search · Rust
- ★ 1r0otk3r/CVE-2025-3248 needs reviewgh_search · Python
- ★ 00ctf/vulhub needs reviewtrickest
- ★ 012-test-12/CVE-2025-3248 needs reviewgh_search · Python
- ★ 0Aimtech7/web-test2 needs reviewtrickest
- ★ 0AmokNepal/langflow needs reviewtrickest
- ★ 0AngelPalominoF/Buho-IA needs reviewtrickest
- ★ 0AngelPalominoF/Martina-IA needs reviewtrickest
- ★ 0
- ★ 0B1ack4sh/Blackash-CVE-2025-3248 needs reviewtrickest
- ★ 0Gideongideon5/langflow-agent needs reviewtrickest
- ★ 0Health-Copilot-AI/langflow needs reviewtrickest
- ★ 0IhorKondratenko/langflow needs reviewtrickest
- ★ 0J1ezds/Vulnerability-Wiki-page needs reviewtrickest
- ★ 0J4c0b-1337x007/ethical-exploit-playground needs reviewtrickest
- ★ 0JeenAI-Team/Langflow-Jeen needs reviewtrickest
- ★ 0JeenAI-Team/Langflow-Ngnix needs reviewtrickest
- ★ 0JeenAI-Team/langflows_v2 needs reviewtrickest
- ★ 0Lern0n/Lernon-POC needs reviewtrickest
- ★ 0MatDupas/Custom-Nmap-Scripts needs reviewtrickest
- ★ 0Pawan22104168/Langflow_UI needs reviewtrickest
- ★ 0PuddinCat/GithubRepoSpider needs reviewtrickest
- ★ 0Rahu7p/MyLangflow needs reviewtrickest
- ★ 0Tetsuro-Copa/langflow needs reviewtrickest
- ★ 0a1batr0ssG/VulhubExpand needs reviewtrickest
- ★ 0aloewright/langflow needs reviewtrickest
- ★ 0arsharma2005/adding-button needs reviewtrickest
- ★ 0aryan-spanda/langflow-main needs reviewtrickest
- ★ 0autocode07/langflow-ai__langflow.087c1a25 needs reviewtrickest
- ★ 0autocode07/langflow-ai__langflow.b093c1fa needs reviewtrickest
- ★ 0bambooqj/cve-2025-3248 needs reviewgh_search · Python
- ★ 0charlesin4g/langflow-main needs reviewtrickest
- ★ 0codevakure/lu-edit needs reviewtrickest
- ★ 0damonfmcmillan/langflow needs reviewtrickest
- ★ 0eeeeeeeeee-code/POC needs reviewtrickest
- ★ 0galgantar/langflow-cve needs reviewtrickest
- ★ 0
- ★ 0ill-deed/Langflow-CVE-2025-3248-Multi-target needs reviewgh_search · Python
- ★ 0issamjr/CVE-2025-3248-Scanner needs reviewtrickest
- ★ 0khulnasoft-lab/AiEXEC needs reviewtrickest
- ★ 0khulnasoft/aiexec needs reviewtrickest
- ★ 0nebari-playground/langflow-cve-2025-3248 needs reviewgh_search
- ★ 0neurdev/langflow-exploit needs reviewtrickest
- ★ 0nvn1729/advisories needs reviewtrickest
- ★ 0oLy0/Vulnerability needs reviewtrickest
- ★ 0packetinside/CISA_BOT needs reviewtrickest
- ★ 0peiqiF4ck/WebFrameworkTools-5.1-main needs reviewtrickest
- ★ 0peiqiF4ck/WebFrameworkTools-5.5 needs reviewtrickest
- ★ 0peiqiF4ck/WebFrameworkTools-5.5-enhance needs reviewtrickest
- ★ 0preemware/langflow-exploit needs reviewtrickest
- ★ 0tonyistark/AIBuilder needs reviewtrickest
- ★ 0ums91/CISA_BOT needs reviewtrickest
- ★ 0waldirjunior/teste-context-langflow needs reviewtrickest
- ★ 0wand3rlust/CVE-2025-3248 needs reviewgh_search · Python
- ★ 0zr1p3r/CVE-2025-3248 needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| PyPI | langflow | 0 → 1.3.0 |
| PyPI | langflow-base | 0 → 0.3.0 |
References
- https://github.com/langflow-ai/langflow/pull/6911
- https://github.com/langflow-ai/langflow/releases/tag/1.3.0
- https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/
- https://www.vulncheck.com/advisories/langflow-unauthenticated-rce
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3248
Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z