CVE-2025-3248 is a critical code injection vulnerability affecting Langflow versions prior to 1.3.0, specifically in the /api/v1/validate/code endpoint. This flaw allows an unauthenticated, remote attacker to execute arbitrary code by sending crafted HTTP requests. With a CVSS score of 9.8 (CRITICAL), the vulnerability has a low attack complexity and no user interaction required, enabling full compromise of confidentiality, integrity, and availability. This CVE is actively exploited in the wild, with public exploit code available (Metasploit, Nuclei, ExploitDB) and significant community discussion and media coverage, including reports of its use to deliver the Flodrix botnet.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.0CPE matchmatch criteria | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.