CVE-2025-3248Critical· 9.8▾ Hadal⚠ Exploited in the wildPoC availableLangflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 20 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 4 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due May 26, 2025
Last analysed / modified upstream
100%
100% → 100%
Exploit-DB · 28 GitHub repos · Metasploit ×1 · Nuclei ×1 (last check)
Added to the CISA catalog on May 5, 2025. Federal remediation due May 26, 2025. View catalog ↗
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
langflow < 1.3.0Upgrade past the affected range:
langflow 1.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-34291High· 8.8Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution
CVE-2026-0770HighLangflow affected by Remote Code Execution via validate_code() exec()
CVE-2026-48519Critical· 9.6Langflow: Unauthenticated RCE in Shareable Playgrounds
CVE-2026-55450Critical· 9.3Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CVE-2026-55255Critical· 9.9Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
CVE-2026-78571High· 8.8IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.