A critical vulnerability in the LangChain-based no-code LLM development platform Langflow exposed internet-facing instances to unauthenticated remote code execution. Tracked as CVE-2025-3248 and rated CVSS 9.8, the flaw was disclosed after researchers showed that unsafe use of Python exec could be abused through Langflow's code-validation functionality, allowing attackers to run arbitrary Python on vulnerable servers.
Security monitoring by MBSD-SOC found exploitation attempts beginning on April 10, 2025, shortly after public disclosure on April 8. Attackers were observed sending crafted POST requests to the /api/v1/validate/code endpoint to execute malicious Python, including attempts to read sensitive files such as /etc/passwd. The report said proof-of-concept code and real-world abuse were already circulating, and urged organizations to update Langflow immediately; telemetry cited the Netherlands and France as the source of roughly half of observed attack traffic.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
MBSD-SOC reported first seeing attacks targeting CVE-2025-3248 on April 10, 2025, shortly after disclosure. The observed activity used crafted POST requests to the /api/v1/validate/code endpoint, including payloads attempting to read /etc/passwd via arbitrary Python execution.
Horizon3.ai published research on abusing Python exec for unauthenticated remote code execution in Langflow AI, providing technical disclosure details referenced by MBSD-SOC.
CVE-2025-3248, a critical unauthenticated remote code execution flaw in the LangChain-based no-code LLM tool Langflow, was disclosed. The MBSD-SOC report states the vulnerability has a CVSS score of 9.8 and notes that proof-of-concept code and abuse reports had already emerged.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.