Junglewise Threat Intelligence

CVE-2025-3248: PYSEC-2026-380 - Langflow Unauth RCE

CVE-2025-3248 · Severity: critical · CVSS 4 · Exploited in the wild · Published 2026-06-29

Technologies: Langflow-Ai Langflow. Vendors: PyPI, Langflow.

Executive brief

Langflow versions prior to 1.3.0 contain a missing authentication vulnerability in the /api/v1/validate/code endpoint. A remote, unauthenticated attacker can exploit this by sending crafted HTTP requests to perform code injection and execute arbitrary code.

Affected products

  • langflow-ai Langflow < 1.3.0

Timeline

  • 2025-04-07: disclosed: NVD Published Date
  • 2025-05-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-05-05: exploited: Reported as exploited in the wild
  • 2025-04-07: patched: Fixed in version 1.3.0 via pull request 6911

Related threats