With evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently revealed major security hole affecting the open-source Langflow platform to its list of known exploited vulnerabilities (KEVs).
Tracked as CVE-2025-3248, the vulnerability has a CVSS score of 9.8 out of 10.0.
According to CISA, Langflow’s /api/v1/validate/code endpoint has a missing authentication vulnerability that enables a remote, unauthenticated attacker to run arbitrary code through carefully constructed HTTP requests.
In particular, it has been discovered that the endpoint incorrectly uses Python’s built-in exec() function on user-supplied code without sufficient sandboxing or authentication, enabling attackers to run arbitrary commands on the server.
The flaw that impacts the majority of the widely used tool’s versions has been fixed in version read more about Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
