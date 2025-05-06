A recently disclosed critical security flaw impacting the open-source Langflow platform has been added to the Known Exploited Vulnerabilities (KEV) catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), citing evidence of active exploitation.

The vulnerability, tracked as CVE-2025-3248, carries a CVSS score of 9.8 out of a maximum of 10.0.

"Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests," CISA said.

Specifically, the endpoint has been found to improperly invoke Python's built-in exec() function on user-supplied code without adequate authentication or sandboxing, thereby allowing attackers to execute arbitrary commands on the server.

The shortcoming, which affects most versions of the popular tool, has been addressed in version 1.3.0 released on March 31, 2025. Horizon3.ai has been credited with discovering and reporting the flaw in February.

According to the company, the vulnerability is "easily exploitable" and allows unauthenticated remote attackers to take control of Langflow servers. A proof-of-concept (PoC) exploit has since been made publicly available as of April 9, 2025, by other researchers.

Data from attack surface management platform Censys shows that there are 466 internet-exposed Langflow instances, with a majority of them concentrated in the United States, Germany, Singapore, India, and China.

It's currently not known how the vulnerability is being abused in real-world attacks, by whom, and for what purpose, although the SANS Technology Institute said it recorded exploit attempts targeting the flaw against its honeypots. Federal Civilian Executive Branch (FCEB) agencies have time until May 26, 2025, to apply the fixes.

"CVE-2025-3248 highlights the risks of executing dynamic code without secure authentication and sandboxing measures," Zscaler noted last month. "This vulnerability serves as a critical reminder for organizations to approach code-validation features with caution, particularly in applications exposed to the internet."