UNKNOWNKNOWN EXPLOITEDRANSOMWARE: KNOWN
CVE-2025-3248
Langflow Missing Authentication Vulnerability
Summary
Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.
References
Includes data from the CISA Known Exploited Vulnerabilities catalog.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.