CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2025-3248: Langflow Unauthenticated RCE Vulnerability

June 30, 2026

Langflow versions before 1.3.0 expose the /api/v1/validate/code endpoint without authentication, allowing remote attackers to execute arbitrary Python code. CVSS score 9.8. Added to CISA KEV catalog on May 5, 2025.