langflow-exploit
Author
preemware
Published
2026-08-09
Stars
0
Forks
0
Repository
Description
PoC for CVE-2025-3248: unauthenticated RCE in Langflow 1.3.0 via /api/v1/validate/code.
CVE-CVE-2025-3248 Details
Severity
CRITICAL
CVSS Score
9.8
CWE
CWE-306
Description
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code....
Related PoCs for CVE-2025-3248
No other PoCs found for this CVE.