logo

CVE-2025-3248: RCE vulnerability in Langflow

ID: 2fdf7d94-3e41-5677-82bc-cac7549d1864

STIX ID: report--2fdf7d94-3e41-5677-82bc-cac7549d1864

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-05-22

Date Updated: 2026-05-01

...
...

This report documents CVE-2025-3248, a vulnerability in Langflow (<1.3.0) where malicious code placed in decorators or default function arguments is executed during AST validation by the /api/v1/validate/code endpoint; the provided PoC demonstrates immediate remote code execution capable of writing files (e.g., hacked.txt) or installing a web shell.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.