VulnerabilitiesLangflow flaw let anyone run code on exposed agent servers
A code validation endpoint executed Python without checking who was asking. CISA listed it as exploited within a month.
6 May 2025
CVE-2025-3248 let anyone with network access to a Langflow server run Python through an unauthenticated code validation endpoint. CISA added it to the Known Exploited Vulnerabilities catalog and researchers later tied exploitation to the Flodrix botnet.
Occurred 7 April 2025 · Disclosed 7 April 2025 · Record updated 13 September 2026
Internet-exposed Langflow instances could be fully compromised. Fixed in version 1.3.0.
VulnerabilitiesA code validation endpoint executed Python without checking who was asking. CISA listed it as exploited within a month.
6 May 2025