All CVEs
Vulnerability intelligence

CVE-2025-3248

CWE-306

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

CVSS Score
9.8
Critical
EPSS — Exploit Probability
100%
Riskier than 100% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2025-05-05
Remediation
Patch available
Federal deadline 2025-05-26
NVD entry Vendor patch PoC / advisory CISA KEV

4 articles across 4 outlets · first covered Jul 3, 2026 · latest Jul 22, 2026

Tracked incidents

Associated threat actors

Coverage timeline