Attackers are actively exploiting CVE-2025-3248, a remote code execution flaw in Langflow’s code validation API, to compromise internet-exposed AI development servers and deploy a customized Gafgyt/BASHLITE malware variant on x86_64 Linux systems. Akamai reported that the intrusion chain uses untrusted Python execution to fetch a Linux binary from a staging server, launch it from a temporary directory, and turn the host into a bot focused on distributed denial-of-service activity rather than cryptomining, persistence, or lateral movement.
The malware reportedly supports multiple flood modes, including UDP, TCP, HOLD, and junk/STD, and uses a modified RC4-based cipher to obscure command-and-control traffic and hinder standard decoding. CISA added CVE-2025-3248 to its Known Exploited Vulnerabilities catalog, while GreyNoise observed hundreds of exploit source IPs targeting the flaw. Defenders are being urged to patch Langflow, isolate AI development environments, place exposed instances behind a WAF, enforce outbound filtering including blocking unauthorized traffic such as port 1337, and deploy YARA detections keyed to the malware’s distinctive cipher seed bytes.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
GreyNoise observed hundreds of source IP addresses exploiting CVE-2025-3248 against internet-exposed Langflow systems. This indicated broad scanning or exploitation activity tied to the flaw.
CISA added Langflow remote code execution flaw CVE-2025-3248 to its Known Exploited Vulnerabilities catalog. The reference cites this as evidence that the vulnerability was being actively exploited.
Akamai reported that the malware used a modified RC4-based mechanism to obscure command-and-control traffic and evade standard decoding tools. The bot supported multiple flood modes including UDP, TCP, HOLD, and junk/STD attacks.
Attackers actively exploited CVE-2025-3248 in Langflow's code validation API endpoint to execute untrusted Python and download a Linux payload on x86_64 systems. The post-exploitation activity delivered a customized Gafgyt/BASHLITE bot focused on DDoS operations rather than cryptomining or lateral movement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.