logo

Langflow Unauth RCE Attack

ID: 8c0d8939-db65-548e-9b9f-cb6dd5e52dc5

STIX ID: report--8c0d8939-db65-548e-9b9f-cb6dd5e52dc5

Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts

Threat Score
82/100

Date Published: 2025-05-15

Date Updated: 2026-07-28

...
...

A critical unauthenticated remote code execution vulnerability (CVE-2025-3248) in Langflow has been actively exploited in the wild; CISA added it to the KEV catalog and multiple reports link its exploitation to campaigns delivering ransomware (JADEPUFFER) and the Flodrix botnet. Organizations using Langflow are advised to upgrade to version 1.3.0 to mitigate this high-risk vulnerability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.