Langflow Missing Authentication Vulnerability

Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.

Published 8 Sep 2026Updated 8 Sep 202632 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.

Affected versions

Langflow: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 52262Langflow 1.3.0 - Remote Code Execution (RCE)VeryLazyTech2025-04-18VerifiedExploit-DB 52364Langflow 1.2.x - Remote Code Execution (RCE)Raghad Abdallah Al-syouf2025-07-16VerifiedPoC-in-GitHub · xuemian168/CVE-2025-3248A vulnerability scanner for CVE-2025-3248 in Langflow applications. 用于扫描 Langflow 应用中 CVE-2025-3248 漏洞的工具。★ 10xuemian1682025-04-10CandidatePoC-in-GitHub · PuddinCat/CVE-2025-3248-POCPOC of CVE-2025-3248, RCE of LangFlow★ 3PuddinCat2025-04-10CandidatePoC-in-GitHub · verylazytech/CVE-2025-3248★ 10verylazytech2025-04-16CandidatePoC-in-GitHub · GraySignal/CVE-2025-3248Scanner and exploit for CVE-2025-3248★ 1GraySignal2025-05-05CandidatePoC-in-GitHub · vigilante-1337/CVE-2025-3248CVE-2025-3248: A critical flaw has been discovered in Langflow that allows malicious actors to execute arbitrary Python code on the target system. This can lead to full remote code execution without authentication, potentially giving attackers control over the server.★ 2vigilante-13372025-05-13CandidatePoC-in-GitHub · Vip3rLi0n/CVE-2025-3248Perform Remote Code Execution using vulnerable API endpoint.★ 1Vip3rLi0n2025-05-27CandidatePoC-in-GitHub · tiemio/RCE-CVE-2025-3248This Python script exploits CVE-2025-3248 to execute arbitrary commands or spawn a reverse shell on a vulnerable system. Authentication is required to use this exploit.★ 1tiemio2025-05-31CandidatePoC-in-GitHub · ynsmroztas/CVE-2025-3248-Langflow-RCECVE-2025-3248 Langflow RCE Exploit★ 17ynsmroztas2025-06-17CandidatePoC-in-GitHub · imbas007/CVE-2025-3248★ 2imbas0072025-06-18CandidatePoC-in-GitHub · 0xgh057r3c0n/CVE-2025-3248Exploit for Langflow AI Remote Code Execution (Unauthenticated)★ 00xgh057r3c0n2025-06-18CandidatePoC-in-GitHub · zapstiko/CVE-2025-3248CVE-2025-3248 — Langflow RCE Exploit★ 1zapstiko2025-06-19CandidatePoC-in-GitHub · 0-d3y/langflow-rce-exploitRemote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]★ 70-d3y2025-06-23CandidatePoC-in-GitHub · dennisec/Mass-CVE-2025-3248Mass-CVE-2025-3248★ 3dennisec2025-06-23CandidatePoC-in-GitHub · ill-deed/Langflow-CVE-2025-3248-Multi-targetLangflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.★ 0ill-deed2025-06-25CandidatePoC-in-GitHub · r0otk3r/CVE-2025-3248★ 1r0otk3r2025-07-06CandidatePoC-in-GitHub · min8282/CVE-2025-3248CVE-2025-3248★ 0min82822025-09-03CandidatePoC-in-GitHub · EQSTLab/CVE-2025-3248Langflow Remote Code Execution★ 3EQSTLab2025-09-15CandidatePoC-in-GitHub · wand3rlust/CVE-2025-3248PoC for achieving RCE in Langflow versions <1.3.0★ 0wand3rlust2025-09-17CandidatePoC-in-GitHub · Kiraly07/Demo_CVE-2025-3248★ 2Kiraly072025-10-01CandidatePoC-in-GitHub · bambooqj/cve-2025-3248Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹 shell、下载器、横向移动等)★ 1bambooqj2025-10-24CandidatePoC-in-GitHub · drackyjr/cve-2025-3248-exploitA comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution vulnerability in Langflow versions ≤ 1.3.0.★ 3drackyjr2025-11-20CandidatePoC-in-GitHub · b0ySie7e/CVE-2025-3248-POC★ 1b0ySie7e2025-12-10CandidatePoC-in-GitHub · 12-test-12/CVE-2025-3248★ 012-test-122026-03-16CandidatePoC-in-GitHub · Atomics-hub/exposecheckDefensive single-target self-check for Langflow CVE-2025-3248 exposure★ 0Atomics-hub2026-07-14CandidatePoC-in-GitHub · preemware/langflow-exploitPoC for CVE-2025-3248: unauthenticated RCE in Langflow < 1.3.0 via /api/v1/validate/code.★ 1preemware2026-08-09CandidatePoC-in-GitHub · hideki233/CVE-2025-3248-Langflow-RCE★ 2hideki2332026-08-28CandidatePoC-in-GitHub · LeotheGGman/Langflow-RCE-CVE-2025-3248★ 0LeotheGGman2026-09-05CandidatePoC-in-GitHub · zoly-zoly/CVE-2025-3248An educational reference and defensive analysis of CVE-2025-3248, a critical code injection vulnerability affecting Langflow.★ 1zoly-zoly2026-09-09Candidate