Langflow Unauth RCE Attack
ID: 8c0d8939-db65-548e-9b9f-cb6dd5e52dc5
STIX ID: report--8c0d8939-db65-548e-9b9f-cb6dd5e52dc5
Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts
Threat Score
A critical unauthenticated remote code execution vulnerability (CVE-2025-3248) in Langflow has been actively exploited in the wild; CISA added it to the KEV catalog and multiple reports link its exploitation to campaigns delivering ransomware (JADEPUFFER) and the Flodrix botnet. Organizations using Langflow are advised to upgrade to version 1.3.0 to mitigate this high-risk vulnerability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
