CVE-2025-3248

Published Apr 7, 2025

Last updated 2 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-3248 is a code injection vulnerability that affects Langflow versions prior to 1.3.0. It exists in the `/api/v1/validate/code` endpoint, where a remote, unauthenticated attacker can send crafted HTTP requests to execute arbitrary code on the server. This vulnerability allows attackers to gain control of vulnerable Langflow servers without needing authentication. To remediate this vulnerability, users are advised to upgrade to Langflow version 1.3.0 or restrict network access to the application.

Description
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
Source
disclosure@vulncheck.com
NVD status
Analyzed
Products
langflow

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Langflow Missing Authentication Vulnerability
Exploit added on
May 5, 2025
Exploit action due
May 26, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

disclosure@vulncheck.com
CWE-306
nvd@nist.gov
CWE-94

Social media

Hype score
Not currently trending
  1. ⚡ 600+ distinct payloads. One autonomous agent. Zero human decisions between initial access and encryption. 🤖 In July 2026, researchers documented the first end-to-end agentic ransomware operation. JADEPUFFER exploited an unpatched Langflow vulnerability (CVE-2025-3248, htt

    @Brandefense

    10 Sept 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. JadePuffer used Langflow CVE-2025-3248, then an exposed Docker socket. Got root. EncForge encrypted AI checkpoints, vector indexes, and training sets. #cybersecurity #infosec #AIsecurity #ransomware #Langflow

    @Caldura7

    5 Sept 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Patch_Diffs -> New_Bugs Langflow, an open-source tool for visually building AI agent and RAG pipelines, is another example of multiple hits by the same flaw. CVE-2025-3248: user input to exec() CVE-2026-33017: same sink, diff endpoint 1. Grep the sink, not the CVE grep -rn

    @BRuteLogic

    26 Aug 2026

    2748 Impressions

    6 Retweets

    30 Likes

    12 Bookmarks

    2 Replies

    0 Quotes

  4. 【サイバーセキュリティ動向分析】 1. AIエージェントによる初の完全自動化ランサムウェア攻撃「JADEPUFFER」の確認 背景 オープンソースのAIアプリケーション構築フレームワーク「Langflow」に存在した深刻な脆

    @FoschiaMatteo

    19 Aug 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CISA lists Langflow RCE (CVE-2025-3248, CVSS 9.8) as actively exploited. A missing auth check lets unauthenticated attackers run code and drop botnets. Upgrade to 1.3.0+ and authenticate every code path. #CyberSecurity #AppSec #OWASP https://t.co/DeRO3Kx0eQ https://t.co/snVY5kZzt

    @OWASPHyderabad

    11 Aug 2026

    101 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  6. When “validate code” actually executes the code 😶 Found an unauthenticated RCE in Langflow (CVE-2025-3248). A code validation endpoint + attacker-controlled Python = 💥 Write-up 👇 https://t.co/nmFjFDIZcO #BugBounty #CyberSecurity #RCE #Langflow

    @M1S00000

    8 Aug 2026

    361 Impressions

    1 Retweet

    7 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  7. Sysdig documented the first agentic ransomware operation. CVE-2025-3248 in Langflow. When a payload failed, the agent fixed and redeployed in 31 seconds. The skill floor for ransomware just dropped. Full CyberScoop article: https://t.co/kgzUu9Zq5a https://t.co/ExVtjucf7Q

    @WKL_cyber

    7 Aug 2026

    776 Impressions

    1 Retweet

    12 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  8. Sysdig's JADEPUFFER used an LLM agent to exploit CVE-2025-3248 in Langflow, self-correcting errors in 31 seconds across 600+ payloads. GodDamn ransomware's signed PoisonX kernel driver blinds EDR before encryption. #DFIR_Radar https://t.co/QXttSwTd2c

    @DFIR_Radar

    6 Aug 2026

    132 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. Unauthenticated code injection in a platform for building LLM applications. We reproduced the public vulnerability, CVE-2025-3248 in Langflow, end to end. The exploit works; the patched build is clean.

    @vulnresearchlab

    5 Aug 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. An AI-run ransomware attack is the first case combining a full agent-driven chain, destructive extortion, and a real target. Entry was via an unpatched Langflow flaw (CVE-2025-3248), chained with an old Nacos bug. See the exploit chain: https://t.co/Ylb3r1RxG5 https://t.co/8IVnCN

    @trendai_RSRCH

    5 Aug 2026

    564 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. JADEPUFFER Agentic Ransomware Automates Database Extortion | CVE-2025-3248 | Read - https://t.co/D0H0TaB4la #infosec #security

    @HOCupdate

    5 Aug 2026

    381 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. TRC analysis shows OpenAI's GPT-5.6 Sol escaped containment during testing, autonomously exploiting CVE-2025-3248 to breach Hugging Face infrastructure. The AI agent performed credential harvesting, lateral movement, and deployed 600+ payloads for persistent access. Runtime

    @aviatrixtrc

    1 Aug 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. An AI-run ransomware attack is the first case combining a full agent-driven chain, destructive extortion, and a real target. Entry was via an unpatched Langflow flaw (CVE-2025-3248), chained with an old Nacos bug. See the exploit chain: https://t.co/Ylb3r1RxG5

    @trendai_RSRCH

    31 Jul 2026

    466 Impressions

    2 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. CISO Daily Briefing: JADEPUFFER ransomware now wipes AI model checkpoints via Langflow CVE-2025-3248 + exposed Docker sockets, $75K-500K to recover; MemGhost's single email corrupts AI agent memory in 56/56 tests, no CVE; Hermes agent ran autonomous post-exploitation unattended

    @cloudsa

    26 Jul 2026

    484 Impressions

    0 Retweets

    3 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  15. 1/3 New ENCFORGE ransomware hunts your AI models. It breaks in through an exposed Langflow endpoint (CVE-2025-3248), then encrypts PyTorch, TensorFlow, SafeTensors and ONNX files, holding your trained models hostage. #Ransomware #AI #CyberSecurity #Malware #Doom https://t.co/N0Xw

    @CyberTLDR

    22 Jul 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  16. Sysdig documented what it calls the first ransomware run entirely by an AI agent. JadePuffer broke into a Langflow server via CVE-2025-3248, then handled recon, credential theft and encryption on its own, fixing a failed login in 31 seconds. #AIsecurity #Ransomware

    @SEatTrend

    22 Jul 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. ENCFORGE es un ransomware que cifra pesos de modelos AI, índices vectoriales y datos de entrenamiento. Se despliega vía Langflow CVE-2025-3248 (CVSS 9.8). https://t.co/VKhhusMqeb

    @NeoteoCom

    21 Jul 2026

    153 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  18. Sysdig: Agentic actor JADEPUFFER returns to Langflow (CVE-2025-3248), deploying ENCFORGE, a purpose-built Go ransomware encrypting AI/ML assets including model checkpoints, vector DBs, and training datasets. https://t.co/C2NZjiVDQH

    @CTITraffic

    21 Jul 2026

    89 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. CISA added Langflow CVE-2026-0770 to KEV. Before that, KEVIntel observed 137 RCE attempts from 46 IPs targeting /api/v1/validate/code. Traffic overlaps with CVE-2025-3248. Same endpoint, different bugs, ambiguous attribution. Full analysis in comments.

    @kev_intel

    21 Jul 2026

    117 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  20. TRC analysis reveals JADEPUFFER exploiting CVE-2025-3248 in Langflow to deploy ENCFORGE ransomware specifically targeting AI model files. Attackers escalated privileges via Docker socket access, then moved laterally to encrypt critical ML assets including model weights and

    @aviatrixtrc

    21 Jul 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. ENCFORGE ransomware targets ~180 AI file types: .safetensors, .ckpt, .onnx, .faiss, .gguf. No leak site, encryption only. Entry via the Langflow KEV flaw CVE-2025-3248. Back up your model weights. https://t.co/OIN4JNyX1A #cybersecurity #ransomware #AIsecurity

    @JNitterauer

    21 Jul 2026

    125 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. JADEPUFFER exploits Langflow's CVE-2025-3248 to deploy ENCFORGE ransomware, encrypting AI models and data. This highlights the urgent need for robust security in AI infrastructure. #CyberSecurity #AI #Ransomware #Langflow #ENCFORGE #JADEPUFFER https://t.co/kV73O17sIP https://t.

    @dailytechonx

    21 Jul 2026

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 🛑 New ENCFORGE ransomware is built to encrypt AI model weights, vector indexes, and training data. Deployed via Langflow CVE-2025-3248 (CVSS 9.8, CISA KEV). Experts link it to the same operator from the earlier agentic attack. Learn how the attack reached host root: https://

    @TheHackersNews

    21 Jul 2026

    17584 Impressions

    18 Retweets

    61 Likes

    14 Bookmarks

    4 Replies

    0 Quotes

  24. 🔒 Ransomware is coming for AI’s crown jewels: model weights, datasets, embeddings, and vector DBs. CVE-2025-3248 proves “the AI stack” is still just software—with very expensive files to encrypt. https://t.co/TErSVA0PUf #ContainerSecurity #Jadepuffer #AiRansomware #Mod

    @windowsforum

    21 Jul 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 自律型AIエージェントJadePuffer独自マルウェアEncForgeを更新し、トレーニングデータセット、ベクトルデータベース、モデルチェックポイントなどのAIアセットを暗号化するように。Sysdig社報告。CVE-2025-3248で過

    @__kokumoto

    21 Jul 2026

    869 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. TRC analysis reveals the autonomous JadePuffer AI agent exploited CVE-2025-3248 to execute ransomware attacks on AI infrastructure. The agent escalated privileges via exposed Docker sockets and moved laterally to encrypt critical model data. Runtime segmentation could have

    @aviatrixtrc

    21 Jul 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. JadePuffer's EncForge ransomware targets AI infrastructure directly, encrypting model checkpoints, vector databases, and training datasets via a Langflow CVE-2025-3248 foothold. Key findings: - Initial access exploits CVE-2025-3248 in Langflow. After credential and token https:

    @DFIR_Radar

    21 Jul 2026

    153 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    1 Quote

  28. JadePuffer ransomware ENCFORGE, a UPX-packed Go binary, re-exploited CVE-2025-3248 in Langflow to target 180 ML file types (.gguf, .safetensors, .pt). It escaped via mounted Docker socket, self-deleted post-encryption. IOCs in the Sysdig report. #DFIR_Radar https://t.co/N3r4w4Wq

    @DFIR_Radar

    20 Jul 2026

    131 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  29. First documented LLM-driven ransomware: JADEPUFFER hit a Langflow auth bypass (CVE-2025-3248, CVSS 9.8), harvested creds, encrypted 1,342 configs. Ransom key wasn't saved — paying wouldn't help. AI-speed offense is operational. #Cybersecurity #CISOs https://t.co/tRcVkMkxvT htt

    @johnmcclure00

    20 Jul 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. JADEPUFFER returns with ENCFORGE, a compiled Go ransomware purpose-built to destroy AI model infrastructure, deployed through CVE-2025-3248 in Langflow after the actor's initial July 2026 campaign. Key findings: - CVE-2025-3248 (CISA KEV, actively exploited) is JADEPUFFER's htt

    @DFIR_Radar

    20 Jul 2026

    154 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  31. CISA's July 10 Langflow deadline is today. First AI agent platform on KEV. CVE-2025-3248 → unauth RCE → JadePuffer used an LLM agent to automate the full attack chain. Your AI infra is now in the same patching queue as your web server. Run Langflow exposed? The clock ran ou

    @fiona_novesai

    18 Jul 2026

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. CISA's first AI agent on KEV. Deadline: today. Langflow CVE-2025-3248 — unauth RCE, patched in May, actively exploited. An agent framework used to build "secure" AI apps is now a federal emergency. The vulnerability was in the agent builder. Not the agent. #AI #AgentSecurit

    @fiona_novesai

    18 Jul 2026

    32 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  33. CVE-2025-3248 and CVE-2026-5027: Langflow RCE Vulnerabilities Explained https://t.co/yV3DzNGXP8

    @Djax_Alpha

    16 Jul 2026

    157 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  34. The first fully autonomous AI ransomware attack has been documented. Sysdig named it JADEPUFFER. It broke into a Langflow server, encrypted 1,342 records, dropped a ransom note — with zero humans typing commands. If you run any exposed AI framework, patch CVE-2025-3248 tonigh

    @FaultSignal_

    15 Jul 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. أول هجوم فدية ينفّذه وكيل LLM بشكل مستقل: استطلاع، سرقة بيانات، تشفير — كل ذلك دون تدخل بشري. المهدد : JadePuffer طريقة الهجوم : Autonomous LLM Agent via Langflow CVE-2025-3248 الجهة

    @KasperskyDev

    15 Jul 2026

    95 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. 🚨 CVE-2025-3248 — now actively exploited in the wild (CISA KEV). Langflow versions prior to 1.3.0 are susceptible to c… Risk 84/100 · EPSS 100% · CVSS 9.8. Patch or mitigate now — attackers are already using it. https://t.co/5FvTTTBV3T #KEV #CVE #Langflow #ActivelyEx

    @BytesNora

    14 Jul 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. JadePuffer (first AI-driven ransomware attack): Sysdig reported what is considered the first end-to-end attack by an AI agent (LLM). The agent hacked a server via a vulnerability (CVE-2025-3248 in Langflow), moved laterally, stole credentials, and encrypted a production data

    @VinceAkrapovic

    14 Jul 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  38. 🚨 IA perde o controle e INVADE servidor Desta vez, o alvo foi o ecossistema do Langflow. O operador autônomo JadePuffer encontrou uma brecha crítica recente (CVE-2025-3248) #segurancadigital #tecnologia #ti #vulnerabilidade #inovacao #dev #inteligenciaartificial #dados ht

    @alcyjones

    14 Jul 2026

    1398 Impressions

    1 Retweet

    5 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  39. Sysdig reveals JadePuffer, allegedly the world's first AI-driven ransomware campaign. It exploited CVE-2025-3248, targeting a Langflow instance with an autonomous AI agent. In one attempt, it fixed a failed login in 31 seconds. https://t.co/EEJv7PyAPd https://t.co/Y5JRcerfyB

    @InfosecurityMag

    14 Jul 2026

    1571 Impressions

    2 Retweets

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  40. JADEPUFFER, the first documented agentic ransomware actor, exploited CVE-2025-3248 in unpatched Langflow to pivot and encrypt 1,342 MySQL/Nacos config items, issuing corrected payloads in 31 seconds. #DFIR_Radar https://t.co/My8oMkzuYC

    @DFIR_Radar

    13 Jul 2026

    169 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  41. Critical RCEs hit ShareFile (CVE-2026-2699/2701, 7/10) & Langflow (CVE-2025-3248/2026-5027, 7/12), threatening data privacy/integrity. Also, Helicone AI-gateway SSRF (CVE-2026-15508, 7/13). Patch now! #Cybersecurity #Vulnerabilities #News

    @YourAnon_irc

    13 Jul 2026

    85 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. Langflow RCE (CVE-2025-3248): how to secure the AI agent frameworks attackers now target https://t.co/kIIjBa18O9

    @eCorpIT

    12 Jul 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. Agentic ransomware went fully autonomous. JADEPUFFER exploited a Langflow RCE (CVE-2025-3248) plus an auth bypass, encrypted 1,342 configs, NO HUMAN INPUT!! Ransomware's skill floor is now whatever it costs to run an agent. https://t.co/vZx6vB7Sb7 #AISecurity #AgenticAI

    @bcassada

    10 Jul 2026

    65 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  44. JadePufferの怖さは、AIが侵入したことではなく、恐喝の手順を最後までつないだ点にある。Sysdigは7/1、LLMエージェントがLangflowのCVE-2025-3248を起点に初期侵入から恐喝まで進めた事例と公表した。

    @connect24h

    10 Jul 2026

    204 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  45. Sysdig documented JADEPUFFER, the first agentic ransomware run end-to-end by an AI agent. It breached Langflow via CVE-2025-3248 and extorted a database. #JADEPUFFER #AgenticRansomware #AI #Ransomware #Langflow #Sysdig #CyberSecurity #InfoSec https://t.co/vuRy4rOvuU

    @Daily_CyberSec

    10 Jul 2026

    374 Impressions

    2 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. An AI agent ran a ransomware attack start to finish, no human after the initial break-in. It exploited an exposed Langflow RCE (CVE-2025-3248), pivoted to a prod MySQL box, encrypted 1,342 config records, and left its own ransom note. Self-hosting agent frameworks? Patch now.

    @anishkargaonkar

    10 Jul 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  47. Sysdig documents first agentic ransomware operation by JadePuffer exploiting CVE-2025-3248 in Langflow. https://t.co/0oWegRG2fy

    @f1tym1

    9 Jul 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. JadePuffer, first fully autonomous ransomware, leveraged CVE-2025-3248 to attack Langflow, signaling a new era of AI-driven cyberattacks https://t.co/C9Qwrtjlkl

    @f1tym1

    9 Jul 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. Sysdig TRT documented JADEPUFFER, first agentic ransomware autonomously exploiting Langflow through CVE-2025-3248. https://t.co/Zg9ZeaQVgH

    @f1tym1

    9 Jul 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. Sysdig observed JADEPUFFER, first agentic ransomware, exploiting CVE-2025-3248 in Langflow. https://t.co/6Gi7AK0P80

    @f1tym1

    9 Jul 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations