logo

Hackers Exploit Critical Langflow Flaw to Unleash Flodrix Botnet

ID: 64642cf2-0e6a-5814-94a3-d3095fee31f3

STIX ID: report--64642cf2-0e6a-5814-94a3-d3095fee31f3

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-06-17

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Trend Micro reports active exploitation of CVE-2025-3248 — a critical (CVSS 9.8) authentication-bypass RCE in Langflow <1.3.0 — where attackers use a public PoC to gain remote shells and deploy the Flodrix botnet (multi-architecture ELF) to enable full system compromise, DDoS, and possible data exposure; the report recommends upgrading to Langflow 1.3.0, restricting public access, and monitoring provided IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.