The vulnerability is tracked as CVE-2025-3248 and is a critical unauthenticated RCE flaw that allows any attacker on the internet to take full control of vulnerable Langflow servers by exploiting an API endpoint flaw. The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has tagged a Langflow remote code execution vulnerability as actively exploited, urging organizations to apply security updates and mitigations as soon as possible. For users of Langflow, it's important to bear in mind Horizon3's remarks about the tool's design, which, according to them, has poor privilege separation, no sandbox, and a history of RCEs "by design" stemming from its nature and intended functionality. CVE-2025-3248 is the first truly unauthenticated RCE flaw in Langflow, and given its active exploitation status, immediate action is required. CVE-2025-3248 was fixed in version 1.3.0, released on April 1, 2025, so it's recommended to upgrade to that version or later to mitigate the risks that arise from the flaw. Those who cannot upgrade to a safe version immediately are recommended to restrict network access to Langflow by putting it behind a firewall, authenticated reverse proxy, or VPN. In vulnerable versions, this endpoint does not safely sandbox or sanitize the input, allowing an attacker to send malicious code to that endpoint and have it executed directly on the server. The latest Langflow version, 1.4.0, was released earlier today and contains a long list of fixes, so users should upgrade to this release. Bill Toulas Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks. Langflow is an open-source visual programming tool for building LLM-powered workflows using LangChain components. Langflow exposes an endpoint (/api/v1/validate/code) designed to validate user-submitted code.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Tue, 06 May 2025 16:10:05 +0000