CVE CVE

CVE-2025-3248

CISA Known Exploited Vulnerability (KEV)

Langflow Missing Authentication Vulnerability

May 5, 2025

May 26, 2025

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary
code.

Weakness Enumeration

CWE-ID CWE Name

CWE-94
Improper Control of Generation of Code (‘Code Injection’)

CWE-306
Missing Authentication for Critical Function

Known Affected Software Configurations


cpe:2.3:a:langflow:langflow:1.0.15:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.3:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.4:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.18:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.6:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.2:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.1.4:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.1.1:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.1.3:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.8:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.13:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.17:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.19:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.1.0:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.1:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.14:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.11:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.7:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.1.2:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.5:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.2.0:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.9:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.16:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.12:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:1.0.10:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.2.5:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.2.3:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.72:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.54:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.2.7:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.74:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.2.9:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.3.1:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.76:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.3.3:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.0:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.32:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.56:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.78:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.11:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.14:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.80:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.16:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.18:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.58:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.82:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.1:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.21:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.84:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.3:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.5:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.22:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.40:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.62:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.86:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.7:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.9:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.2.2:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.71:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.2.4:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.53:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.2.6:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.73:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.2.8:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.31:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.3.0:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.75:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.3.2:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.55:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.3.4:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.77:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.10:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.21:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.12:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.79:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.15:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.57:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.17:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.81:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.19:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.33:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.20:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.83:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.2:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.61:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.4:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.85:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.6:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.19:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.4.8:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.87:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.63:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.5.0:-:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.88:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.5.0:alpha0:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.5.0:alpha1:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.44:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.0.64:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.1.0:*:*:*:*:*:*:*

cpe:2.3:a:langflow:langflow:0.1.2:*:*:*:*:*:*:*

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
9.8
Severity:

CRITICAL

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2

Not defined