Known vulnerability record

CVE-2025-3248

Langflow Missing Authentication Vulnerability

Stable IDcve:CVE-2025-3248Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

Langflow Missing Authentication Vulnerability

Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.

Keep the signals separate

CVSS severitycriticalScore 9.8 · source VulnCheck
EPSS probability100.0%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2025-05-05
Ransomware useknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2025-04-07
CVE modified
2026-07-14
KEV date added
2025-05-05
Dataset fetched
2026-08-21T03:55:07.209Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.