Description

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

INFO

Published Date :

2025-04-07T14:22:38.980Z

Last Modified :

2025-11-29T02:05:33.261Z

Source :

VulnCheck
AFFECTED PRODUCTS

The following products are affected by CVE-2025-3248 vulnerability.

Vendors Products
Langflow
  • Langflow

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact