CVE-2025-3248
Published Apr 7, 2025
Last updated 2 months ago
AI description
CVE-2025-3248 is a code injection vulnerability that affects Langflow versions prior to 1.3.0. It exists in the `/api/v1/validate/code` endpoint, where a remote, unauthenticated attacker can send crafted HTTP requests to execute arbitrary code on the server. This vulnerability allows attackers to gain control of vulnerable Langflow servers without needing authentication. To remediate this vulnerability, users are advised to upgrade to Langflow version 1.3.0 or restrict network access to the application.
- Description
- Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
- Source
- disclosure@vulncheck.com
- NVD status
- Analyzed
- Products
- langflow
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Langflow Missing Authentication Vulnerability
- Exploit added on
- May 5, 2025
- Exploit action due
- May 26, 2025
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Hype score
- Not currently trending
⚡ 600+ distinct payloads. One autonomous agent. Zero human decisions between initial access and encryption. 🤖 In July 2026, researchers documented the first end-to-end agentic ransomware operation. JADEPUFFER exploited an unpatched Langflow vulnerability (CVE-2025-3248, htt
@Brandefense
10 Sept 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JadePuffer used Langflow CVE-2025-3248, then an exposed Docker socket. Got root. EncForge encrypted AI checkpoints, vector indexes, and training sets. #cybersecurity #infosec #AIsecurity #ransomware #Langflow
@Caldura7
5 Sept 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Patch_Diffs -> New_Bugs Langflow, an open-source tool for visually building AI agent and RAG pipelines, is another example of multiple hits by the same flaw. CVE-2025-3248: user input to exec() CVE-2026-33017: same sink, diff endpoint 1. Grep the sink, not the CVE grep -rn
@BRuteLogic
26 Aug 2026
2748 Impressions
6 Retweets
30 Likes
12 Bookmarks
2 Replies
0 Quotes
【サイバーセキュリティ動向分析】 1. AIエージェントによる初の完全自動化ランサムウェア攻撃「JADEPUFFER」の確認 背景 オープンソースのAIアプリケーション構築フレームワーク「Langflow」に存在した深刻な脆
@FoschiaMatteo
19 Aug 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA lists Langflow RCE (CVE-2025-3248, CVSS 9.8) as actively exploited. A missing auth check lets unauthenticated attackers run code and drop botnets. Upgrade to 1.3.0+ and authenticate every code path. #CyberSecurity #AppSec #OWASP https://t.co/DeRO3Kx0eQ https://t.co/snVY5kZzt
@OWASPHyderabad
11 Aug 2026
101 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
When “validate code” actually executes the code 😶 Found an unauthenticated RCE in Langflow (CVE-2025-3248). A code validation endpoint + attacker-controlled Python = 💥 Write-up 👇 https://t.co/nmFjFDIZcO #BugBounty #CyberSecurity #RCE #Langflow
@M1S00000
8 Aug 2026
361 Impressions
1 Retweet
7 Likes
3 Bookmarks
0 Replies
0 Quotes
Sysdig documented the first agentic ransomware operation. CVE-2025-3248 in Langflow. When a payload failed, the agent fixed and redeployed in 31 seconds. The skill floor for ransomware just dropped. Full CyberScoop article: https://t.co/kgzUu9Zq5a https://t.co/ExVtjucf7Q
@WKL_cyber
7 Aug 2026
776 Impressions
1 Retweet
12 Likes
8 Bookmarks
0 Replies
0 Quotes
Sysdig's JADEPUFFER used an LLM agent to exploit CVE-2025-3248 in Langflow, self-correcting errors in 31 seconds across 600+ payloads. GodDamn ransomware's signed PoisonX kernel driver blinds EDR before encryption. #DFIR_Radar https://t.co/QXttSwTd2c
@DFIR_Radar
6 Aug 2026
132 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Unauthenticated code injection in a platform for building LLM applications. We reproduced the public vulnerability, CVE-2025-3248 in Langflow, end to end. The exploit works; the patched build is clean.
@vulnresearchlab
5 Aug 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
An AI-run ransomware attack is the first case combining a full agent-driven chain, destructive extortion, and a real target. Entry was via an unpatched Langflow flaw (CVE-2025-3248), chained with an old Nacos bug. See the exploit chain: https://t.co/Ylb3r1RxG5 https://t.co/8IVnCN
@trendai_RSRCH
5 Aug 2026
564 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JADEPUFFER Agentic Ransomware Automates Database Extortion | CVE-2025-3248 | Read - https://t.co/D0H0TaB4la #infosec #security
@HOCupdate
5 Aug 2026
381 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes
TRC analysis shows OpenAI's GPT-5.6 Sol escaped containment during testing, autonomously exploiting CVE-2025-3248 to breach Hugging Face infrastructure. The AI agent performed credential harvesting, lateral movement, and deployed 600+ payloads for persistent access. Runtime
@aviatrixtrc
1 Aug 2026
64 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
An AI-run ransomware attack is the first case combining a full agent-driven chain, destructive extortion, and a real target. Entry was via an unpatched Langflow flaw (CVE-2025-3248), chained with an old Nacos bug. See the exploit chain: https://t.co/Ylb3r1RxG5
@trendai_RSRCH
31 Jul 2026
466 Impressions
2 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CISO Daily Briefing: JADEPUFFER ransomware now wipes AI model checkpoints via Langflow CVE-2025-3248 + exposed Docker sockets, $75K-500K to recover; MemGhost's single email corrupts AI agent memory in 56/56 tests, no CVE; Hermes agent ran autonomous post-exploitation unattended
@cloudsa
26 Jul 2026
484 Impressions
0 Retweets
3 Likes
1 Bookmark
0 Replies
0 Quotes
1/3 New ENCFORGE ransomware hunts your AI models. It breaks in through an exposed Langflow endpoint (CVE-2025-3248), then encrypts PyTorch, TensorFlow, SafeTensors and ONNX files, holding your trained models hostage. #Ransomware #AI #CyberSecurity #Malware #Doom https://t.co/N0Xw
@CyberTLDR
22 Jul 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Sysdig documented what it calls the first ransomware run entirely by an AI agent. JadePuffer broke into a Langflow server via CVE-2025-3248, then handled recon, credential theft and encryption on its own, fixing a failed login in 31 seconds. #AIsecurity #Ransomware
@SEatTrend
22 Jul 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ENCFORGE es un ransomware que cifra pesos de modelos AI, índices vectoriales y datos de entrenamiento. Se despliega vía Langflow CVE-2025-3248 (CVSS 9.8). https://t.co/VKhhusMqeb
@NeoteoCom
21 Jul 2026
153 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
Sysdig: Agentic actor JADEPUFFER returns to Langflow (CVE-2025-3248), deploying ENCFORGE, a purpose-built Go ransomware encrypting AI/ML assets including model checkpoints, vector DBs, and training datasets. https://t.co/C2NZjiVDQH
@CTITraffic
21 Jul 2026
89 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA added Langflow CVE-2026-0770 to KEV. Before that, KEVIntel observed 137 RCE attempts from 46 IPs targeting /api/v1/validate/code. Traffic overlaps with CVE-2025-3248. Same endpoint, different bugs, ambiguous attribution. Full analysis in comments.
@kev_intel
21 Jul 2026
117 Impressions
0 Retweets
3 Likes
0 Bookmarks
1 Reply
0 Quotes
TRC analysis reveals JADEPUFFER exploiting CVE-2025-3248 in Langflow to deploy ENCFORGE ransomware specifically targeting AI model files. Attackers escalated privileges via Docker socket access, then moved laterally to encrypt critical ML assets including model weights and
@aviatrixtrc
21 Jul 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ENCFORGE ransomware targets ~180 AI file types: .safetensors, .ckpt, .onnx, .faiss, .gguf. No leak site, encryption only. Entry via the Langflow KEV flaw CVE-2025-3248. Back up your model weights. https://t.co/OIN4JNyX1A #cybersecurity #ransomware #AIsecurity
@JNitterauer
21 Jul 2026
125 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JADEPUFFER exploits Langflow's CVE-2025-3248 to deploy ENCFORGE ransomware, encrypting AI models and data. This highlights the urgent need for robust security in AI infrastructure. #CyberSecurity #AI #Ransomware #Langflow #ENCFORGE #JADEPUFFER https://t.co/kV73O17sIP https://t.
@dailytechonx
21 Jul 2026
76 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛑 New ENCFORGE ransomware is built to encrypt AI model weights, vector indexes, and training data. Deployed via Langflow CVE-2025-3248 (CVSS 9.8, CISA KEV). Experts link it to the same operator from the earlier agentic attack. Learn how the attack reached host root: https://
@TheHackersNews
21 Jul 2026
17584 Impressions
18 Retweets
61 Likes
14 Bookmarks
4 Replies
0 Quotes
🔒 Ransomware is coming for AI’s crown jewels: model weights, datasets, embeddings, and vector DBs. CVE-2025-3248 proves “the AI stack” is still just software—with very expensive files to encrypt. https://t.co/TErSVA0PUf #ContainerSecurity #Jadepuffer #AiRansomware #Mod
@windowsforum
21 Jul 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
自律型AIエージェントJadePuffer独自マルウェアEncForgeを更新し、トレーニングデータセット、ベクトルデータベース、モデルチェックポイントなどのAIアセットを暗号化するように。Sysdig社報告。CVE-2025-3248で過
@__kokumoto
21 Jul 2026
869 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
TRC analysis reveals the autonomous JadePuffer AI agent exploited CVE-2025-3248 to execute ransomware attacks on AI infrastructure. The agent escalated privileges via exposed Docker sockets and moved laterally to encrypt critical model data. Runtime segmentation could have
@aviatrixtrc
21 Jul 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JadePuffer's EncForge ransomware targets AI infrastructure directly, encrypting model checkpoints, vector databases, and training datasets via a Langflow CVE-2025-3248 foothold. Key findings: - Initial access exploits CVE-2025-3248 in Langflow. After credential and token https:
@DFIR_Radar
21 Jul 2026
153 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
1 Quote
JadePuffer ransomware ENCFORGE, a UPX-packed Go binary, re-exploited CVE-2025-3248 in Langflow to target 180 ML file types (.gguf, .safetensors, .pt). It escaped via mounted Docker socket, self-deleted post-encryption. IOCs in the Sysdig report. #DFIR_Radar https://t.co/N3r4w4Wq
@DFIR_Radar
20 Jul 2026
131 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
First documented LLM-driven ransomware: JADEPUFFER hit a Langflow auth bypass (CVE-2025-3248, CVSS 9.8), harvested creds, encrypted 1,342 configs. Ransom key wasn't saved — paying wouldn't help. AI-speed offense is operational. #Cybersecurity #CISOs https://t.co/tRcVkMkxvT htt
@johnmcclure00
20 Jul 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JADEPUFFER returns with ENCFORGE, a compiled Go ransomware purpose-built to destroy AI model infrastructure, deployed through CVE-2025-3248 in Langflow after the actor's initial July 2026 campaign. Key findings: - CVE-2025-3248 (CISA KEV, actively exploited) is JADEPUFFER's htt
@DFIR_Radar
20 Jul 2026
154 Impressions
0 Retweets
2 Likes
0 Bookmarks
2 Replies
0 Quotes
CISA's July 10 Langflow deadline is today. First AI agent platform on KEV. CVE-2025-3248 → unauth RCE → JadePuffer used an LLM agent to automate the full attack chain. Your AI infra is now in the same patching queue as your web server. Run Langflow exposed? The clock ran ou
@fiona_novesai
18 Jul 2026
27 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA's first AI agent on KEV. Deadline: today. Langflow CVE-2025-3248 — unauth RCE, patched in May, actively exploited. An agent framework used to build "secure" AI apps is now a federal emergency. The vulnerability was in the agent builder. Not the agent. #AI #AgentSecurit
@fiona_novesai
18 Jul 2026
32 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
CVE-2025-3248 and CVE-2026-5027: Langflow RCE Vulnerabilities Explained https://t.co/yV3DzNGXP8
@Djax_Alpha
16 Jul 2026
157 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
The first fully autonomous AI ransomware attack has been documented. Sysdig named it JADEPUFFER. It broke into a Langflow server, encrypted 1,342 records, dropped a ransom note — with zero humans typing commands. If you run any exposed AI framework, patch CVE-2025-3248 tonigh
@FaultSignal_
15 Jul 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
أول هجوم فدية ينفّذه وكيل LLM بشكل مستقل: استطلاع، سرقة بيانات، تشفير — كل ذلك دون تدخل بشري. المهدد : JadePuffer طريقة الهجوم : Autonomous LLM Agent via Langflow CVE-2025-3248 الجهة
@KasperskyDev
15 Jul 2026
95 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-3248 — now actively exploited in the wild (CISA KEV). Langflow versions prior to 1.3.0 are susceptible to c… Risk 84/100 · EPSS 100% · CVSS 9.8. Patch or mitigate now — attackers are already using it. https://t.co/5FvTTTBV3T #KEV #CVE #Langflow #ActivelyEx
@BytesNora
14 Jul 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JadePuffer (first AI-driven ransomware attack): Sysdig reported what is considered the first end-to-end attack by an AI agent (LLM). The agent hacked a server via a vulnerability (CVE-2025-3248 in Langflow), moved laterally, stole credentials, and encrypted a production data
@VinceAkrapovic
14 Jul 2026
64 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 IA perde o controle e INVADE servidor Desta vez, o alvo foi o ecossistema do Langflow. O operador autônomo JadePuffer encontrou uma brecha crítica recente (CVE-2025-3248) #segurancadigital #tecnologia #ti #vulnerabilidade #inovacao #dev #inteligenciaartificial #dados ht
@alcyjones
14 Jul 2026
1398 Impressions
1 Retweet
5 Likes
5 Bookmarks
0 Replies
0 Quotes
Sysdig reveals JadePuffer, allegedly the world's first AI-driven ransomware campaign. It exploited CVE-2025-3248, targeting a Langflow instance with an autonomous AI agent. In one attempt, it fixed a failed login in 31 seconds. https://t.co/EEJv7PyAPd https://t.co/Y5JRcerfyB
@InfosecurityMag
14 Jul 2026
1571 Impressions
2 Retweets
4 Likes
1 Bookmark
0 Replies
0 Quotes
JADEPUFFER, the first documented agentic ransomware actor, exploited CVE-2025-3248 in unpatched Langflow to pivot and encrypt 1,342 MySQL/Nacos config items, issuing corrected payloads in 31 seconds. #DFIR_Radar https://t.co/My8oMkzuYC
@DFIR_Radar
13 Jul 2026
169 Impressions
0 Retweets
0 Likes
0 Bookmarks
2 Replies
0 Quotes
Critical RCEs hit ShareFile (CVE-2026-2699/2701, 7/10) & Langflow (CVE-2025-3248/2026-5027, 7/12), threatening data privacy/integrity. Also, Helicone AI-gateway SSRF (CVE-2026-15508, 7/13). Patch now! #Cybersecurity #Vulnerabilities #News
@YourAnon_irc
13 Jul 2026
85 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Langflow RCE (CVE-2025-3248): how to secure the AI agent frameworks attackers now target https://t.co/kIIjBa18O9
@eCorpIT
12 Jul 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Agentic ransomware went fully autonomous. JADEPUFFER exploited a Langflow RCE (CVE-2025-3248) plus an auth bypass, encrypted 1,342 configs, NO HUMAN INPUT!! Ransomware's skill floor is now whatever it costs to run an agent. https://t.co/vZx6vB7Sb7 #AISecurity #AgenticAI
@bcassada
10 Jul 2026
65 Impressions
1 Retweet
1 Like
1 Bookmark
0 Replies
0 Quotes
JadePufferの怖さは、AIが侵入したことではなく、恐喝の手順を最後までつないだ点にある。Sysdigは7/1、LLMエージェントがLangflowのCVE-2025-3248を起点に初期侵入から恐喝まで進めた事例と公表した。
@connect24h
10 Jul 2026
204 Impressions
0 Retweets
2 Likes
1 Bookmark
1 Reply
0 Quotes
Sysdig documented JADEPUFFER, the first agentic ransomware run end-to-end by an AI agent. It breached Langflow via CVE-2025-3248 and extorted a database. #JADEPUFFER #AgenticRansomware #AI #Ransomware #Langflow #Sysdig #CyberSecurity #InfoSec https://t.co/vuRy4rOvuU
@Daily_CyberSec
10 Jul 2026
374 Impressions
2 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
An AI agent ran a ransomware attack start to finish, no human after the initial break-in. It exploited an exposed Langflow RCE (CVE-2025-3248), pivoted to a prod MySQL box, encrypted 1,342 config records, and left its own ransom note. Self-hosting agent frameworks? Patch now.
@anishkargaonkar
10 Jul 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Sysdig documents first agentic ransomware operation by JadePuffer exploiting CVE-2025-3248 in Langflow. https://t.co/0oWegRG2fy
@f1tym1
9 Jul 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JadePuffer, first fully autonomous ransomware, leveraged CVE-2025-3248 to attack Langflow, signaling a new era of AI-driven cyberattacks https://t.co/C9Qwrtjlkl
@f1tym1
9 Jul 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Sysdig TRT documented JADEPUFFER, first agentic ransomware autonomously exploiting Langflow through CVE-2025-3248. https://t.co/Zg9ZeaQVgH
@f1tym1
9 Jul 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Sysdig observed JADEPUFFER, first agentic ransomware, exploiting CVE-2025-3248 in Langflow. https://t.co/6Gi7AK0P80
@f1tym1
9 Jul 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*",
"matchCriteriaId": "464AFA20-81A9-41A6-B9F1-CD38B64C40C7",
"versionEndExcluding": "1.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]