Skip to content
LangflowGHSA-rvqx-wpfh-mfx7

Langflow Unauth RCE

CriticalCVE-2025-3248 · Published Jun 17, 2025 · updated Jun 29, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
langflow
PyPI
< 1.3.01.3.0
Details and references

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A
Severity from
GitHub (reviewed advisory)
Weakness
CWE-94
Also known as
CVE-2025-3248, PYSEC-2025-36, PYSEC-2026-380

More Langflow advisories

All Langflow
DateAdvisory
Aug 252025Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
CVE-2025-57760High8.8fixed in 1.5.1
Dec 62025Langflow CORS misconfiguration enables Account Takeover and RCE
CVE-2025-34291Critical8.8fixed in 1.7.0
Dec 192025Langflow vulnerable to Server-Side Request Forgery
CVE-2025-68477High7.7fixed in 1.7.1
Dec 192025External Control of File Name or Path in Langflow
CVE-2025-68478High7.1fixed in 1.7.1
Jan 2Langflow Missing Authentication on Critical API Endpoints
CVE-2026-21445Highfixed in 1.7.1
Jan 23Langflow affected by Remote Code Execution via validate_code() exec()
CVE-2026-0770Highno fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.