Published April 7, 2025
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary...
Full analysis pending. Showing NVD description excerpt.
Affected Systems
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| langflow | pip | < 1.3.0 | 1.3.0 |
| langflow | pip | — | No patch |
| langflow-base | pip | < 0.3.0 | 0.3.0 |
Severity & Risk
CVSS 3.1
9.8 / 10
EPSS
92.5%
chance of exploitation in 30 days
KEV Status
Actively Exploited
Sophistication
N/A
Recommended Action
Patch available
Update langflow to version 1.3.0
Update langflow-base to version 0.3.0
Compliance Impact
Compliance analysis pending. Sign in for full compliance mapping when available.
Technical Details
NVD Description
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
Weaknesses (CWE)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References
- cisa.gov/known-exploited-vulnerabilities-catalog US Gov
- github.com/langflow-ai/langflow/pull/6911 Patch
- github.com/langflow-ai/langflow/releases/tag/1.3.0 Release
- horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/ Exploit 3rd Party
- vulncheck.com/advisories/langflow-unauthenticated-rce 3rd Party
- github.com/advisories/GHSA-rvqx-wpfh-mfx7
- github.com/langflow-ai/langflow/commit/faac4db133de32fcb6d483fa9ff52f40ce42bdc0
- github.com/langflow-ai/langflow/pull/6911
- github.com/langflow-ai/langflow/releases/tag/1.3.0
- github.com/langflow-ai/langflow/security/advisories/GHSA-rvqx-wpfh-mfx7
- nvd.nist.gov/vuln/detail/CVE-2025-3248
- cisa.gov/known-exploited-vulnerabilities-catalog
- horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai
- vulncheck.com/advisories/langflow-unauthenticated-rce
Timeline
Published
April 7, 2025
Last Modified
November 6, 2025
First Seen
April 7, 2025