AI description
CVE-2025-3248 is a code injection vulnerability that affects Langflow versions prior to 1.3.0. It exists in the `/api/v1/validate/code` endpoint, where a remote, unauthenticated attacker can send crafted HTTP requests to execute arbitrary code on the server. This vulnerability allows attackers to gain control of vulnerable Langflow servers without needing authentication. To remediate this vulnerability, users are advised to upgrade to Langflow version 1.3.0 or restrict network access to the application.
- Description
- Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
- Source
- disclosure@vulncheck.com
- NVD status
- Analyzed
- Products
- langflow
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Langflow Missing Authentication Vulnerability
- Exploit added on
- May 5, 2025
- Exploit action due
- May 26, 2025
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Hype score
- Not currently trending
CISA's July 10 Langflow deadline is today. First AI agent platform on KEV. CVE-2025-3248 → unauth RCE → JadePuffer used an LLM agent to automate the full attack chain. Your AI infra is now in the same patching queue as your web server. Run Langflow exposed? The clock ran ou
@fiona_novesai
18 Jul 2026
27 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA's first AI agent on KEV. Deadline: today. Langflow CVE-2025-3248 — unauth RCE, patched in May, actively exploited. An agent framework used to build "secure" AI apps is now a federal emergency. The vulnerability was in the agent builder. Not the agent. #AI #AgentSecurit
@fiona_novesai
18 Jul 2026
32 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
CVE-2025-3248 and CVE-2026-5027: Langflow RCE Vulnerabilities Explained https://t.co/yV3DzNGXP8
@Djax_Alpha
16 Jul 2026
157 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
The first fully autonomous AI ransomware attack has been documented. Sysdig named it JADEPUFFER. It broke into a Langflow server, encrypted 1,342 records, dropped a ransom note — with zero humans typing commands. If you run any exposed AI framework, patch CVE-2025-3248 tonigh
@FaultSignal_
15 Jul 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
أول هجوم فدية ينفّذه وكيل LLM بشكل مستقل: استطلاع، سرقة بيانات، تشفير — كل ذلك دون تدخل بشري. المهدد : JadePuffer طريقة الهجوم : Autonomous LLM Agent via Langflow CVE-2025-3248 الجهة
@KasperskyDev
15 Jul 2026
95 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-3248 — now actively exploited in the wild (CISA KEV). Langflow versions prior to 1.3.0 are susceptible to c… Risk 84/100 · EPSS 100% · CVSS 9.8. Patch or mitigate now — attackers are already using it. https://t.co/5FvTTTBV3T #KEV #CVE #Langflow #ActivelyEx
@BytesNora
14 Jul 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JadePuffer (first AI-driven ransomware attack): Sysdig reported what is considered the first end-to-end attack by an AI agent (LLM). The agent hacked a server via a vulnerability (CVE-2025-3248 in Langflow), moved laterally, stole credentials, and encrypted a production data
@VinceAkrapovic
14 Jul 2026
64 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 IA perde o controle e INVADE servidor Desta vez, o alvo foi o ecossistema do Langflow. O operador autônomo JadePuffer encontrou uma brecha crítica recente (CVE-2025-3248) #segurancadigital #tecnologia #ti #vulnerabilidade #inovacao #dev #inteligenciaartificial #dados ht
@alcyjones
14 Jul 2026
1398 Impressions
1 Retweet
5 Likes
5 Bookmarks
0 Replies
0 Quotes
Sysdig reveals JadePuffer, allegedly the world's first AI-driven ransomware campaign. It exploited CVE-2025-3248, targeting a Langflow instance with an autonomous AI agent. In one attempt, it fixed a failed login in 31 seconds. https://t.co/EEJv7PyAPd https://t.co/Y5JRcerfyB
@InfosecurityMag
14 Jul 2026
1571 Impressions
2 Retweets
4 Likes
1 Bookmark
0 Replies
0 Quotes
JADEPUFFER, the first documented agentic ransomware actor, exploited CVE-2025-3248 in unpatched Langflow to pivot and encrypt 1,342 MySQL/Nacos config items, issuing corrected payloads in 31 seconds. #DFIR_Radar https://t.co/My8oMkzuYC
@DFIR_Radar
13 Jul 2026
169 Impressions
0 Retweets
0 Likes
0 Bookmarks
2 Replies
0 Quotes
Critical RCEs hit ShareFile (CVE-2026-2699/2701, 7/10) & Langflow (CVE-2025-3248/2026-5027, 7/12), threatening data privacy/integrity. Also, Helicone AI-gateway SSRF (CVE-2026-15508, 7/13). Patch now! #Cybersecurity #Vulnerabilities #News
@YourAnon_irc
13 Jul 2026
85 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Langflow RCE (CVE-2025-3248): how to secure the AI agent frameworks attackers now target https://t.co/kIIjBa18O9
@eCorpIT
12 Jul 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Agentic ransomware went fully autonomous. JADEPUFFER exploited a Langflow RCE (CVE-2025-3248) plus an auth bypass, encrypted 1,342 configs, NO HUMAN INPUT!! Ransomware's skill floor is now whatever it costs to run an agent. https://t.co/vZx6vB7Sb7 #AISecurity #AgenticAI
@bcassada
10 Jul 2026
65 Impressions
1 Retweet
1 Like
1 Bookmark
0 Replies
0 Quotes
JadePufferの怖さは、AIが侵入したことではなく、恐喝の手順を最後までつないだ点にある。Sysdigは7/1、LLMエージェントがLangflowのCVE-2025-3248を起点に初期侵入から恐喝まで進めた事例と公表した。
@connect24h
10 Jul 2026
204 Impressions
0 Retweets
2 Likes
1 Bookmark
1 Reply
0 Quotes
Sysdig documented JADEPUFFER, the first agentic ransomware run end-to-end by an AI agent. It breached Langflow via CVE-2025-3248 and extorted a database. #JADEPUFFER #AgenticRansomware #AI #Ransomware #Langflow #Sysdig #CyberSecurity #InfoSec https://t.co/vuRy4rOvuU
@Daily_CyberSec
10 Jul 2026
374 Impressions
2 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
An AI agent ran a ransomware attack start to finish, no human after the initial break-in. It exploited an exposed Langflow RCE (CVE-2025-3248), pivoted to a prod MySQL box, encrypted 1,342 config records, and left its own ransom note. Self-hosting agent frameworks? Patch now.
@anishkargaonkar
10 Jul 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Sysdig documents first agentic ransomware operation by JadePuffer exploiting CVE-2025-3248 in Langflow. https://t.co/0oWegRG2fy
@f1tym1
9 Jul 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Sysdig TRT documented JADEPUFFER, first agentic ransomware autonomously exploiting Langflow through CVE-2025-3248. https://t.co/Zg9ZeaQVgH
@f1tym1
9 Jul 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JadePuffer, first fully autonomous ransomware, leveraged CVE-2025-3248 to attack Langflow, signaling a new era of AI-driven cyberattacks https://t.co/C9Qwrtjlkl
@f1tym1
9 Jul 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Sysdig observed JADEPUFFER, first agentic ransomware, exploiting CVE-2025-3248 in Langflow. https://t.co/6Gi7AK0P80
@f1tym1
9 Jul 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
https://t.co/NxSQ1IuJUG Just in: JADEPUFFER — the documented case of an LLM agent running a full ransomware https://t.co/nHVhyvysst researchers at Sysdig detailed an extortion campaign where, after initial access via a known Langflow vulnerability (CVE-2025-3248), an LLM-drive
@nicezestAI
9 Jul 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Security researchers at Sysdig just documented the first known fully autonomous AI ransomware attack. An AI agent called JADEPUFFER exploited CVE-2025-3248 (a 9.8 CVSS unauthenticated RCE in Langflow) to execute the entire kill chain on its own: initial access, credential
@SanctusVoid_
9 Jul 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Sysdig documents first agentic ransomware operation by JadePuffer exploiting CVE-2025-3248 in Langflow. https://t.co/KujRd84qfZ
@f1tym1
8 Jul 2026
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JADEPUFFER: Sysdig documented the first ransomware operation run end-to-end by an autonomous AI agent. No human at the keyboard. It chained CVE-2025-3248 (Langflow, KEV) → CVE-2021-29441 (Nacos) and encrypted a production DB itself. 🧵 the fix runbook 👇 https://t.co/dCXz
@zerohuntai
8 Jul 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
JadePuffer ransomware uses an LLM agent to autonomously execute a full attack chain, marking the first documented end-to-end agentic ransomware operation. Entry point was CVE-2025-3248 (CVSS 9.8, CISA KEV) in Langflow. - CVE-2025-3248 is an unauthenticated RCE in Langflow's http
@DFIR_Radar
8 Jul 2026
251 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
1 Quote
JadePuffer, first fully autonomous ransomware, leveraged CVE-2025-3248 to attack Langflow, signaling a new era of AI-driven cyberattacks https://t.co/9gqW1G95Dc
@f1tym1
7 Jul 2026
75 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Sysdig TRT documented JADEPUFFER, first agentic ransomware autonomously exploiting Langflow through CVE-2025-3248. https://t.co/XwWtSRJy1D
@f1tym1
7 Jul 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Langflowの脆弱性CVE-2025-3248がランサムウェアに悪用された。米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性(KEV)カタログが更新。2025年5月にKEVカタログに採録されていたもの。 ht
@__kokumoto
7 Jul 2026
666 Impressions
0 Retweets
4 Likes
0 Bookmarks
0 Replies
0 Quotes
Sysdig observed JADEPUFFER, first agentic ransomware, exploiting CVE-2025-3248 in Langflow. https://t.co/SrNEYRMmvA
@f1tym1
7 Jul 2026
70 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
JADEPUFFER is the first documented agentic ransomware, driven end to end by an LLM with no human operator. It exploited CVE-2025-3248 in an internet-facing Langflow instance, pivoted to production systems, and destroyed a MySQL database in a single autonomous run. - https://t.co
@DFIR_Radar
7 Jul 2026
214 Impressions
0 Retweets
0 Likes
1 Bookmark
1 Reply
0 Quotes
OSS DEV TOOL → AI RANSOMWARE LAUNCHPAD JadePuffer: Langflow CVE-2025-3248 used to: – Pivot into live production DBs – Encrypt configs + data – Drop ransom notes—autonomously If your AI app runs exposed, you're not shipping fast. You're handing an AI attacker the door
@PrinceBuildsAI
7 Jul 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Healthcare IT & Devs: JadePuffer is the first fully autonomous AI ransomware. It exploits Langflow (CVE-2025-3248) to encrypt data with zero human intervention. The shift to agentic threats is here. Patch your AI orchestration tools now. #CyberSecurity https://t.co/6LzjTJiKYp
@Techsico_IT
7 Jul 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🇺🇸 AI-driven ransomware JadePuffer shifts cybercrime geopolitics. Sysdig reveals it exploits CVE-2025-3248 autonomously. Losers? Traditional cybersecurity firms. Winners? AI chip manufacturers. Expect regulatory crackdowns by Q4 2026. Autonomy changes the game.
@GlobalAIWatcher
7 Jul 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
JadePuffer ran the first documented agentic ransomware attack in late June 2026, exploiting CVE-2025-3248 in Langflow then using an AI agent to autonomously recon, move laterally, and encrypt a MySQL/Nacos server with 600+ payloads. #DFIR_Radar https://t.co/m2Gjv2mYCF
@DFIR_Radar
7 Jul 2026
169 Impressions
0 Retweets
0 Likes
0 Bookmarks
2 Replies
0 Quotes
Sysdig documents the first AI-agent ransomware operation: an LLM exploited CVE-2025-3248 in Langflow, moved laterally, and encrypted 1,342 production database records with no human directing each step. #Cybersecurity #AiAgents Link in the first comment 👇 https://t.co/AYM36mj
@awagents
7 Jul 2026
108 Impressions
0 Retweets
0 Likes
1 Bookmark
1 Reply
0 Quotes
CVE-2025-3248: Does Agentic Ransomware Mark a New Cybercrime Paradigm? https://t.co/8OQvxwMi9o #CyberSecurity #Ransomware #IncidentResponse
@cyber_newsroom
6 Jul 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-3248: Sysdig's Discovery of Agentic Ransomware Exposes Security Gaps https://t.co/J6g87Z5dOO #CVE2025 #Ransomware #CyberSecurity
@cyber_newsroom
6 Jul 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-3248: Sysdig's Findings Reveal Broader Implications of AI-Driven Ransomware https://t.co/iJ94A2I7sb #CyberSecurity #AI #Ransomware
@cyber_newsroom
6 Jul 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-3248 Exposed by JadePuffer: The Dawn of Agentic Ransomware https://t.co/dpbEDxkrhv #CyberSecurity #Ransomware #ThreatIntelligence
@cyber_newsroom
6 Jul 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-3248: JadePuffer's Agentic Ransomware Redefines Cybercrime https://t.co/SBzoTAiuqt #CyberSecurity #Ransomware #CyberCrime
@cyber_newsroom
6 Jul 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Ransomware attackers exploited CVE-2025-3248 in Langflow to steal secrets and encrypt data, using AI-like code for quick fixes and leaving no decryption key. https://t.co/kvVo1oj8vr
@f1tym1
6 Jul 2026
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Old bug. New ransomware playbook. A 2025 Langflow RCE — CVE-2025-3248 — is back in the spotlight after researchers tied it to a 2026 AI-agent ransomware operation. The lesson: “patched last year” doesn’t mean “fixed in your environment.” Patch. Remove exposu
@CyberAlliance26
6 Jul 2026
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 AI just joined the ransomware playbook. Attackers exploited exposed Langflow via CVE-2025-3248 to run Python, hunt secrets, pivot, and encrypt 1,342 Nacos configs. Patch Langflow. Kill public exposure. Rotate keys. Hunt now. #CyberSecurity #AI #Ransomware #InfoSec https:/
@CyberAlliance26
6 Jul 2026
22 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes
jadepuffer is the first documented end-to-end llm ransomware case from sysdig. the agent chained langflow cve-2025-3248 with nacos flaws, harvested openai keys, pivoted and wiped 1342 db records then self-corrected in 31 seconds with zero human input. this removes the human http
@boggyagent
6 Jul 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JadePuffer, claimed as the first fully LLM-driven ransomware, exploited CVE-2025-3248 in Langflow, then chained CVE-2021-29441 to reach a production Nacos MySQL server. #DFIR_Radar https://t.co/H5uCUL9Mf7
@DFIR_Radar
6 Jul 2026
136 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Cadena de ataque hecha por LLM. En cuestión de minutos: CVE-2025-3248 en Langflow Volcado PostgreSQL local Pivote hacia MySQL Cifrado https://t.co/YIIpOMFQUY
@albjodbor
6 Jul 2026
60 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
Investigadores de Sysdig han documentado el primer caso de ransomware, JadePuffer, que utiliza un agente de IA para automatizar ataques. Este agente explota la vulnerabilidad CVE-2025-3248 para robar credenciales y cifrar datos en 31 segundos. https://t.co/Aav9548Fn4 https://t.c
@ProtAAPP
6 Jul 2026
477 Impressions
4 Retweets
8 Likes
2 Bookmarks
1 Reply
0 Quotes
An AI agent just ran a full ransomware attack with no human at the keyboard. Sysdig calls it JADEPUFFER. It found an exposed Langflow server, hit a known RCE (CVE-2025-3248), stole creds, and encrypted 1,342 production records. Every bug it used was old. https://t.co/K4H6mvQPrN
@N_aBo_
5 Jul 2026
182 Impressions
0 Retweets
6 Likes
0 Bookmarks
0 Replies
0 Quotes
pro tip: patch CVE-2025-3248 if your AI stack includes Langflow. Sysdig documented the first ransomware op run entirely by an AI agent. it entered via that CVE, harvested LLM API keys and cloud creds automatically. your unpatched agent is someone else's attack surface.
@SeijinJung
5 Jul 2026
120 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
AI ran ransomware end to end, no human in the loop. JADEPUFFER extorted a database through Langflow: - Exploited CVE-2025-3248 for unauthenticated RCE - Hit Nacos, encrypted 1,342 config items First agentic ransomware in the wild. https://t.co/YYKIRDdukJ
@so_sthbryan
5 Jul 2026
137 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*",
"matchCriteriaId": "464AFA20-81A9-41A6-B9F1-CD38B64C40C7",
"versionEndExcluding": "1.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]