All CVEs
Vulnerability intelligence

CVE-2025-3248

Langflow Missing Authentication Vulnerability

Langflow Langflow CWE-306

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

CVSS Score
9.8
Critical
EPSS — Exploit Probability
100%
Riskier than 100% of all CVEs · checked 2026-10-01
Exploitation
Confirmed in the wild
Used in ransomware campaigns
Remediation
Patch available
Federal deadline 2025-05-26
CISA required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2025-05-26.

NVD entry Vendor patch PoC / advisory CISA KEV

6 articles across 5 outlets · first covered Jul 3, 2026 · latest Sep 30, 2026

Associated threat actors

Coverage timeline

Related CVEs — Langflow