Investigate
Search by exact CVE, vulnerability wording, recognized software name, or product and version. Examples: Python 3.7, Adobe ColdFusion 2021, remote code execution, or CVE-2025-12345.
Search terms and exact CVE identifiers are sent to the public NVD API. Only public CVE identifiers — never uploaded company or asset data — are used for the other enrichment sources.
Results
Showing the 1 most recent result for “CVE-2025-3248”.
-
95Immediate CVE-2025-3248 ExigentCISA KEVActively Exploited Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. CVSS v3.1 9.8
Severity CRITICAL CVSS v3.1 9.8 EPSS 99+Out-of-Band / Urgent Remediation
Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
Vulnerability type: CWE-306 | CWE-94 — Code injection
Impacted software or hardware
- langflow Software — < 1.3.0
Patch status: Patch or fixed version identified
Fixed versions: langflow: update to 1.3.0 or later
Remediation: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation basis: CISA KEV required action
CISA KEV: known exploited. Remediation due 2025-05-26. Known ransomware campaign use: Known.Research this vulnerability
- NIST NVD — Scores, weaknesses, products, and references
- CVE.org — Authoritative CVE Program record
- CISA KEV — Known exploitation and federal remediation action
- Tenable — Detection plugins and Tenable analysis
- Rapid7 — Threat, exploit, and remediation research
- GitHub Advisory — Open-source package advisories
- Snyk — Package versions and available fixes
★ My Watchlist (0)
Saved only in this browser (localStorage) — no account, nothing sent to EVULNABLE. Clearing your browser data clears this too. The Excel and PDF exports are built right here in your browser from those saved items; nothing is sent to EVULNABLE for those either.
