CVE-2025-3248

Published Apr 7, 2025

Last updated 6 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-3248 is a code injection vulnerability that affects Langflow versions prior to 1.3.0. It exists in the `/api/v1/validate/code` endpoint, where a remote, unauthenticated attacker can send crafted HTTP requests to execute arbitrary code on the server. This vulnerability allows attackers to gain control of vulnerable Langflow servers without needing authentication. To remediate this vulnerability, users are advised to upgrade to Langflow version 1.3.0 or restrict network access to the application.

Description
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
Source
disclosure@vulncheck.com
NVD status
Analyzed
Products
langflow

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Langflow Missing Authentication Vulnerability
Exploit added on
May 5, 2025
Exploit action due
May 26, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

disclosure@vulncheck.com
CWE-306
nvd@nist.gov
CWE-94

Social media

Hype score
Not currently trending
  1. CISA's July 10 Langflow deadline is today. First AI agent platform on KEV. CVE-2025-3248 → unauth RCE → JadePuffer used an LLM agent to automate the full attack chain. Your AI infra is now in the same patching queue as your web server. Run Langflow exposed? The clock ran ou

    @fiona_novesai

    18 Jul 2026

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CISA's first AI agent on KEV. Deadline: today. Langflow CVE-2025-3248 — unauth RCE, patched in May, actively exploited. An agent framework used to build "secure" AI apps is now a federal emergency. The vulnerability was in the agent builder. Not the agent. #AI #AgentSecurit

    @fiona_novesai

    18 Jul 2026

    32 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  3. CVE-2025-3248 and CVE-2026-5027: Langflow RCE Vulnerabilities Explained https://t.co/yV3DzNGXP8

    @Djax_Alpha

    16 Jul 2026

    157 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. The first fully autonomous AI ransomware attack has been documented. Sysdig named it JADEPUFFER. It broke into a Langflow server, encrypted 1,342 records, dropped a ransom note — with zero humans typing commands. If you run any exposed AI framework, patch CVE-2025-3248 tonigh

    @FaultSignal_

    15 Jul 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. أول هجوم فدية ينفّذه وكيل LLM بشكل مستقل: استطلاع، سرقة بيانات، تشفير — كل ذلك دون تدخل بشري. المهدد : JadePuffer طريقة الهجوم : Autonomous LLM Agent via Langflow CVE-2025-3248 الجهة

    @KasperskyDev

    15 Jul 2026

    95 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 CVE-2025-3248 — now actively exploited in the wild (CISA KEV). Langflow versions prior to 1.3.0 are susceptible to c… Risk 84/100 · EPSS 100% · CVSS 9.8. Patch or mitigate now — attackers are already using it. https://t.co/5FvTTTBV3T #KEV #CVE #Langflow #ActivelyEx

    @BytesNora

    14 Jul 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. JadePuffer (first AI-driven ransomware attack): Sysdig reported what is considered the first end-to-end attack by an AI agent (LLM). The agent hacked a server via a vulnerability (CVE-2025-3248 in Langflow), moved laterally, stole credentials, and encrypted a production data

    @VinceAkrapovic

    14 Jul 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. 🚨 IA perde o controle e INVADE servidor Desta vez, o alvo foi o ecossistema do Langflow. O operador autônomo JadePuffer encontrou uma brecha crítica recente (CVE-2025-3248) #segurancadigital #tecnologia #ti #vulnerabilidade #inovacao #dev #inteligenciaartificial #dados ht

    @alcyjones

    14 Jul 2026

    1398 Impressions

    1 Retweet

    5 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  9. Sysdig reveals JadePuffer, allegedly the world's first AI-driven ransomware campaign. It exploited CVE-2025-3248, targeting a Langflow instance with an autonomous AI agent. In one attempt, it fixed a failed login in 31 seconds. https://t.co/EEJv7PyAPd https://t.co/Y5JRcerfyB

    @InfosecurityMag

    14 Jul 2026

    1571 Impressions

    2 Retweets

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  10. JADEPUFFER, the first documented agentic ransomware actor, exploited CVE-2025-3248 in unpatched Langflow to pivot and encrypt 1,342 MySQL/Nacos config items, issuing corrected payloads in 31 seconds. #DFIR_Radar https://t.co/My8oMkzuYC

    @DFIR_Radar

    13 Jul 2026

    169 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  11. Critical RCEs hit ShareFile (CVE-2026-2699/2701, 7/10) & Langflow (CVE-2025-3248/2026-5027, 7/12), threatening data privacy/integrity. Also, Helicone AI-gateway SSRF (CVE-2026-15508, 7/13). Patch now! #Cybersecurity #Vulnerabilities #News

    @YourAnon_irc

    13 Jul 2026

    85 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Langflow RCE (CVE-2025-3248): how to secure the AI agent frameworks attackers now target https://t.co/kIIjBa18O9

    @eCorpIT

    12 Jul 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Agentic ransomware went fully autonomous. JADEPUFFER exploited a Langflow RCE (CVE-2025-3248) plus an auth bypass, encrypted 1,342 configs, NO HUMAN INPUT!! Ransomware's skill floor is now whatever it costs to run an agent. https://t.co/vZx6vB7Sb7 #AISecurity #AgenticAI

    @bcassada

    10 Jul 2026

    65 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  14. JadePufferの怖さは、AIが侵入したことではなく、恐喝の手順を最後までつないだ点にある。Sysdigは7/1、LLMエージェントがLangflowのCVE-2025-3248を起点に初期侵入から恐喝まで進めた事例と公表した。

    @connect24h

    10 Jul 2026

    204 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  15. Sysdig documented JADEPUFFER, the first agentic ransomware run end-to-end by an AI agent. It breached Langflow via CVE-2025-3248 and extorted a database. #JADEPUFFER #AgenticRansomware #AI #Ransomware #Langflow #Sysdig #CyberSecurity #InfoSec https://t.co/vuRy4rOvuU

    @Daily_CyberSec

    10 Jul 2026

    374 Impressions

    2 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. An AI agent ran a ransomware attack start to finish, no human after the initial break-in. It exploited an exposed Langflow RCE (CVE-2025-3248), pivoted to a prod MySQL box, encrypted 1,342 config records, and left its own ransom note. Self-hosting agent frameworks? Patch now.

    @anishkargaonkar

    10 Jul 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  17. Sysdig documents first agentic ransomware operation by JadePuffer exploiting CVE-2025-3248 in Langflow. https://t.co/0oWegRG2fy

    @f1tym1

    9 Jul 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Sysdig TRT documented JADEPUFFER, first agentic ransomware autonomously exploiting Langflow through CVE-2025-3248. https://t.co/Zg9ZeaQVgH

    @f1tym1

    9 Jul 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. JadePuffer, first fully autonomous ransomware, leveraged CVE-2025-3248 to attack Langflow, signaling a new era of AI-driven cyberattacks https://t.co/C9Qwrtjlkl

    @f1tym1

    9 Jul 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Sysdig observed JADEPUFFER, first agentic ransomware, exploiting CVE-2025-3248 in Langflow. https://t.co/6Gi7AK0P80

    @f1tym1

    9 Jul 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. https://t.co/NxSQ1IuJUG Just in: JADEPUFFER — the documented case of an LLM agent running a full ransomware https://t.co/nHVhyvysst researchers at Sysdig detailed an extortion campaign where, after initial access via a known Langflow vulnerability (CVE-2025-3248), an LLM-drive

    @nicezestAI

    9 Jul 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Security researchers at Sysdig just documented the first known fully autonomous AI ransomware attack. An AI agent called JADEPUFFER exploited CVE-2025-3248 (a 9.8 CVSS unauthenticated RCE in Langflow) to execute the entire kill chain on its own: initial access, credential

    @SanctusVoid_

    9 Jul 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Sysdig documents first agentic ransomware operation by JadePuffer exploiting CVE-2025-3248 in Langflow. https://t.co/KujRd84qfZ

    @f1tym1

    8 Jul 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. JADEPUFFER: Sysdig documented the first ransomware operation run end-to-end by an autonomous AI agent. No human at the keyboard. It chained CVE-2025-3248 (Langflow, KEV) → CVE-2021-29441 (Nacos) and encrypted a production DB itself. 🧵 the fix runbook 👇 https://t.co/dCXz

    @zerohuntai

    8 Jul 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  25. JadePuffer ransomware uses an LLM agent to autonomously execute a full attack chain, marking the first documented end-to-end agentic ransomware operation. Entry point was CVE-2025-3248 (CVSS 9.8, CISA KEV) in Langflow. - CVE-2025-3248 is an unauthenticated RCE in Langflow's http

    @DFIR_Radar

    8 Jul 2026

    251 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    1 Quote

  26. JadePuffer, first fully autonomous ransomware, leveraged CVE-2025-3248 to attack Langflow, signaling a new era of AI-driven cyberattacks https://t.co/9gqW1G95Dc

    @f1tym1

    7 Jul 2026

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. Sysdig TRT documented JADEPUFFER, first agentic ransomware autonomously exploiting Langflow through CVE-2025-3248. https://t.co/XwWtSRJy1D

    @f1tym1

    7 Jul 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. Langflowの脆弱性CVE-2025-3248がランサムウェアに悪用された。米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性(KEV)カタログが更新。2025年5月にKEVカタログに採録されていたもの。 ht

    @__kokumoto

    7 Jul 2026

    666 Impressions

    0 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. Sysdig observed JADEPUFFER, first agentic ransomware, exploiting CVE-2025-3248 in Langflow. https://t.co/SrNEYRMmvA

    @f1tym1

    7 Jul 2026

    70 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  30. JADEPUFFER is the first documented agentic ransomware, driven end to end by an LLM with no human operator. It exploited CVE-2025-3248 in an internet-facing Langflow instance, pivoted to production systems, and destroyed a MySQL database in a single autonomous run. - https://t.co

    @DFIR_Radar

    7 Jul 2026

    214 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  31. OSS DEV TOOL → AI RANSOMWARE LAUNCHPAD JadePuffer: Langflow CVE-2025-3248 used to: – Pivot into live production DBs – Encrypt configs + data – Drop ransom notes—autonomously If your AI app runs exposed, you're not shipping fast. You're handing an AI attacker the door

    @PrinceBuildsAI

    7 Jul 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. Healthcare IT & Devs: JadePuffer is the first fully autonomous AI ransomware. It exploits Langflow (CVE-2025-3248) to encrypt data with zero human intervention. The shift to agentic threats is here. Patch your AI orchestration tools now. #CyberSecurity https://t.co/6LzjTJiKYp

    @Techsico_IT

    7 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. 🇺🇸 AI-driven ransomware JadePuffer shifts cybercrime geopolitics. Sysdig reveals it exploits CVE-2025-3248 autonomously. Losers? Traditional cybersecurity firms. Winners? AI chip manufacturers. Expect regulatory crackdowns by Q4 2026. Autonomy changes the game.

    @GlobalAIWatcher

    7 Jul 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  34. JadePuffer ran the first documented agentic ransomware attack in late June 2026, exploiting CVE-2025-3248 in Langflow then using an AI agent to autonomously recon, move laterally, and encrypt a MySQL/Nacos server with 600+ payloads. #DFIR_Radar https://t.co/m2Gjv2mYCF

    @DFIR_Radar

    7 Jul 2026

    169 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  35. Sysdig documents the first AI-agent ransomware operation: an LLM exploited CVE-2025-3248 in Langflow, moved laterally, and encrypted 1,342 production database records with no human directing each step. #Cybersecurity #AiAgents Link in the first comment 👇 https://t.co/AYM36mj

    @awagents

    7 Jul 2026

    108 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  36. CVE-2025-3248: Does Agentic Ransomware Mark a New Cybercrime Paradigm? https://t.co/8OQvxwMi9o #CyberSecurity #Ransomware #IncidentResponse

    @cyber_newsroom

    6 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. CVE-2025-3248: Sysdig's Discovery of Agentic Ransomware Exposes Security Gaps https://t.co/J6g87Z5dOO #CVE2025 #Ransomware #CyberSecurity

    @cyber_newsroom

    6 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. CVE-2025-3248: Sysdig's Findings Reveal Broader Implications of AI-Driven Ransomware https://t.co/iJ94A2I7sb #CyberSecurity #AI #Ransomware

    @cyber_newsroom

    6 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. CVE-2025-3248 Exposed by JadePuffer: The Dawn of Agentic Ransomware https://t.co/dpbEDxkrhv #CyberSecurity #Ransomware #ThreatIntelligence

    @cyber_newsroom

    6 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. CVE-2025-3248: JadePuffer's Agentic Ransomware Redefines Cybercrime https://t.co/SBzoTAiuqt #CyberSecurity #Ransomware #CyberCrime

    @cyber_newsroom

    6 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. Ransomware attackers exploited CVE-2025-3248 in Langflow to steal secrets and encrypt data, using AI-like code for quick fixes and leaving no decryption key. https://t.co/kvVo1oj8vr

    @f1tym1

    6 Jul 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. 🚨 Old bug. New ransomware playbook. A 2025 Langflow RCE — CVE-2025-3248 — is back in the spotlight after researchers tied it to a 2026 AI-agent ransomware operation. The lesson: “patched last year” doesn’t mean “fixed in your environment.” Patch. Remove exposu

    @CyberAlliance26

    6 Jul 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. 🚨 AI just joined the ransomware playbook. Attackers exploited exposed Langflow via CVE-2025-3248 to run Python, hunt secrets, pivot, and encrypt 1,342 Nacos configs. Patch Langflow. Kill public exposure. Rotate keys. Hunt now. #CyberSecurity #AI #Ransomware #InfoSec https:/

    @CyberAlliance26

    6 Jul 2026

    22 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. jadepuffer is the first documented end-to-end llm ransomware case from sysdig. the agent chained langflow cve-2025-3248 with nacos flaws, harvested openai keys, pivoted and wiped 1342 db records then self-corrected in 31 seconds with zero human input. this removes the human http

    @boggyagent

    6 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. JadePuffer, claimed as the first fully LLM-driven ransomware, exploited CVE-2025-3248 in Langflow, then chained CVE-2021-29441 to reach a production Nacos MySQL server. #DFIR_Radar https://t.co/H5uCUL9Mf7

    @DFIR_Radar

    6 Jul 2026

    136 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  46. Cadena de ataque hecha por LLM. En cuestión de minutos: CVE-2025-3248 en Langflow Volcado PostgreSQL local Pivote hacia MySQL Cifrado https://t.co/YIIpOMFQUY

    @albjodbor

    6 Jul 2026

    60 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  47. Investigadores de Sysdig han documentado el primer caso de ransomware, JadePuffer, que utiliza un agente de IA para automatizar ataques. Este agente explota la vulnerabilidad CVE-2025-3248 para robar credenciales y cifrar datos en 31 segundos. https://t.co/Aav9548Fn4 https://t.c

    @ProtAAPP

    6 Jul 2026

    477 Impressions

    4 Retweets

    8 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  48. An AI agent just ran a full ransomware attack with no human at the keyboard. Sysdig calls it JADEPUFFER. It found an exposed Langflow server, hit a known RCE (CVE-2025-3248), stole creds, and encrypted 1,342 production records. Every bug it used was old. https://t.co/K4H6mvQPrN

    @N_aBo_

    5 Jul 2026

    182 Impressions

    0 Retweets

    6 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. pro tip: patch CVE-2025-3248 if your AI stack includes Langflow. Sysdig documented the first ransomware op run entirely by an AI agent. it entered via that CVE, harvested LLM API keys and cloud creds automatically. your unpatched agent is someone else's attack surface.

    @SeijinJung

    5 Jul 2026

    120 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  50. AI ran ransomware end to end, no human in the loop. JADEPUFFER extorted a database through Langflow: - Exploited CVE-2025-3248 for unauthenticated RCE - Hit Nacos, encrypted 1,342 config items First agentic ransomware in the wild. https://t.co/YYKIRDdukJ

    @so_sthbryan

    5 Jul 2026

    137 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations