Sunday, 13 September 2026
8 agent hacks today 8 vs yesterday (0)

Langflow code-validation endpoint gives unauthenticated remote code execution

CVE-2025-3248 let anyone with network access to a Langflow server run Python through an unauthenticated code validation endpoint. CISA added it to the Known Exploited Vulnerabilities catalog and researchers later tied exploitation to the Flodrix botnet.

Occurred 7 April 2025 · Disclosed 7 April 2025 · Record updated 13 September 2026

Impact

Internet-exposed Langflow instances could be fully compromised. Fixed in version 1.3.0.

Our coverage

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-3248
  2. horizon3.aihttps://horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/
  3. cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog