Langflow: CVE-2025-3248: Active Exploitation
ID: 7f0d6afc-9e73-559d-92f5-f4e0f4ecc63a
STIX ID: report--7f0d6afc-9e73-559d-92f5-f4e0f4ecc63a
Feed Name: Recorded Future Blog
CVE-2025-3248 is a critical unauthenticated remote code execution vulnerability in Langflow versions prior to 1.3.0 that stems from unsafe use of Python's compile/exec when validating function ASTs (decorators and default arguments can execute during compilation). The report notes active exploitation indicators (CISA KEV listing, ~1,050 Shodan-exposed instances, 361 malicious IPs observed by Greynoise), public PoCs on GitHub, and recommends immediate patching to Langflow 1.3.0 or network restrictions to block the /api/v1/validate/code endpoint.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
