CVE-2025-3248: RCE vulnerability in Langflow
ID: 2fdf7d94-3e41-5677-82bc-cac7549d1864
STIX ID: report--2fdf7d94-3e41-5677-82bc-cac7549d1864
Feed Name: Zscaler Security Research Blog
Threat Score
This report documents CVE-2025-3248, a vulnerability in Langflow (<1.3.0) where malicious code placed in decorators or default function arguments is executed during AST validation by the /api/v1/validate/code endpoint; the provided PoC demonstrates immediate remote code execution capable of writing files (e.g., hacked.txt) or installing a web shell.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
