Vulnerability intelligence
CVE-2025-3248
Langflow Missing Authentication Vulnerability
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
CVSS Score
9.8
Critical
EPSS — Exploit Probability
100%
Riskier than 100% of all CVEs · checked 2026-10-01
Exploitation
Confirmed in the wild
Used in ransomware campaigns
Remediation
Patch available
Federal deadline 2025-05-26
CISA required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2025-05-26.
6 articles across 5 outlets · first covered Jul 3, 2026 · latest Sep 30, 2026
Associated threat actors
Coverage timeline
-
Google Warns N Day Flaws Are Driving a Surge in Exploitationcloud.google.com · Sep 30, 2026
-
JADEPUFFER Marks the First AI-Driven Agentic Ransomware Attacksecurityonline.info · Jul 10, 2026
-
LLM Driven Ransomware Automates Attack via Langflow CVE-2025-3248www.darkreading.com · Jul 6, 2026
-
JADEPUFFER AI ransomware exploits Langflow flaw CVE-2025-3248securityaffairs.com · Jul 3, 2026
-
Agentic AI Used to Conduct Ransomware Attack via Langflowwww.securityweek.com · Jul 3, 2026
-
U.S. CISA adds a Langflow flaw to its Known Exploited Vulnerabilities catalogsecurityaffairs.com · Mar 26, 2026