CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-3248

KEV · ransomware Critical · CVSS 9.8

Langflow — Unauthenticated Remote Code Execution via Python code injection (exec)

CVSS
9.8
nvd
EPSS
KEV
Listed
ransomware
Class
oss containerizable
CWE-306, CWE-94, CWE-306

Description

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

Search profile — drives PoC discovery

Symbols /api/v1/validate/codeexecvalidate_codelangflowlangflow-basecode injection
Keywords CVE-2025-3248Langflow RCELangflow code injectionlangflow validate code endpointlangflow unauthenticated RCElangflow /api/v1/validate/code exploitlangflow exec RCE PoClangflow 1.3.0 vulnerability
Versions: < 1.3.0

Ranked PoCs (80) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

PyPI langflow 0 → 1.3.0
PyPI langflow-base 0 → 0.3.0

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z