Langflow unauthenticated code injection in validate/code endpoint
Langflow < 1.3.0: unauthenticated code injection allows RCE via crafted HTTP requests to /api/v1/validate/code. CVSS 9.8 critical. CISA KEV 2025-05-05.
- Vendor
- Langflow
- Product
- Langflow
- CVSS
- 9.8
- EPSS (exploit probability)
- 100.0%
- Status
- kevransomware use
- CISA patch-by (BOD 22-01)
- Published
Langflow versions prior to 1.3.0 contain a code injection vulnerability in the /api/v1/validate/code endpoint. A remote, unauthenticated attacker can send crafted HTTP requests to execute arbitrary code on the server. No credentials required, no user interaction required.
CISA added CVE-2025-3248 to the Known Exploited Vulnerabilities catalog on 2025-05-05, confirming active exploitation in the wild. Source: NVD.
Affected versions
Langflow versions prior to 1.3.0.
What to do
Upgrade to Langflow 1.3.0 or later. Given Langflow’s history of repeated critical RCE vulnerabilities in the same platform — this is the first of five KEV entries in fourteen months — upgrading to the current 1.9.x release rather than stopping at 1.3.0 is the correct posture. Each interim KEV entry (CVE-2026-33017, CVE-2025-34291, CVE-2026-55255, CVE-2026-0770) represents an additional unpatched path if you stop short of current.
Any instance reachable from the internet on a version below 1.3.0 should be treated as likely compromised and investigated before relying on it.
