9.8

CVE-2025-3248

Warning
Media report
Exploit

Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code

Langflow versions prior to 1.3.0 are susceptible to code injection in 
the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary
code.
Data is provided by the National Vulnerability Database (NVD)
LangflowLangflow Version < 1.3.0

05.05.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog

Langflow Missing Authentication Vulnerability

Vulnerability

Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.

Description

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Required actions
EPSS Metrics
Type Source Score Percentile
EPSS FIRST.org 99.99% 1
CVSS Metrics
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
disclosure@vulncheck.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

A VulnDex account is required to access Vulnerability Intelligence.
VulnDex Intel
Media Report
08.07.2026 12:19
A VulnDex account is required to access Vulnerability Intelligence.
VulnDex Intel
Media Report
08.07.2026 08:34
A VulnDex account is required to access Vulnerability Intelligence.
VulnDex Intel
Media Report
07.07.2026 12:48
A VulnDex account is required to access Vulnerability Intelligence.
VulnDex Intel
Media Report
04.07.2026 16:31
A VulnDex account is required to access Vulnerability Intelligence.
VulnDex Intel
Media Report
03.07.2026 21:31
A VulnDex account is required to access Vulnerability Intelligence.
VulnDex Intel
Media Report
02.07.2026 11:30
A VulnDex account is required to access Vulnerability Intelligence.
VulnDex Intel
Media Report
30.06.2026 19:28
A VulnDex account is required to access Vulnerability Intelligence.
VulnDex Intel
Media Report
10.06.2026 23:29
A VulnDex account is required to access Vulnerability Intelligence.
VulnDex Intel
Media Report
10.04.2026 15:18
A VulnDex account is required to access Vulnerability Intelligence.
VulnDex Intel
Media Report
26.03.2026 20:39
A VulnDex account is required to access Vulnerability Intelligence.
VulnDex Intel
Media Report
20.03.2026 17:36
A VulnDex account is required to access Vulnerability Intelligence.
VulnDex Intel
Media Report
09.08.2025 11:36
https://github.com/langflow-ai/langflow/pull/6911
Patch
https://github.com/langflow-ai/langflow/releases/tag/1.3.0
Release Notes
https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/
Third Party Advisory
Exploit
https://www.vulncheck.com/advisories/langflow-unauthenticated-rce
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3248
US Government Resource