A serious security vulnerability in the open-source platform Langflow was recently added to the U.S. Cybersecurity and Infrastructure Security Agency’s ( CISA ) List of Known Exploitable Vulnerabilities (KEV ). This means that the vulnerability has already been exploited by malicious actors.

This vulnerability, tracked as CVE-2025-3248, has been rated with a CVSS score of 9.8/10, indicating extremely high risk.
CISA said the issue is located in /api/v1/validate/code and allows unauthorized users to send modified HTTP requests and execute arbitrary code on the server.
See also: CISA: Broadcom Fabric OS, CommVault, Active! vulnerabilities in KEV Catalog
The vulnerability affects multiple versions of the Langflow platform, but was fixed in version 1.3.0, released on March 31, 2025.The initial report was made by the company Horizon3.ai, which identified the issue earlier in February.
According to Horizon3.ai, exploiting the vulnerability is extremely simple and could allow any unauthorized attacker to take complete control of a Langflow server. In fact, as of April 9, 2025 , a proof-of-concept exploit is already circulating online .
Hundreds of Langflow installations exposed online
According to data from the Censys platform, 466 Langflow systems have been identified that are publicly accessible over the Internet. Most of them are located in countries such as the United States, Germany, Singapore, India, and China .
See also: CISA: SonicWall VPN flaw is actively used in attacks
So far, there are no details on how the CVE-2025-3248 has been exploited in real-world attacks. We also don't know who is exploiting it or for what purposes.
The US federal government has given Federal Civilian Executive Branch (FCEB) agencies until May 26, 2025 to implement the necessary security updates and fixes.
CISA KEV Catalog
The KEV catalog is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.

Overall, CISA is a great help in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, governments , and local authorities, to improve the security of digital systems.
See also: CISA warns of vulnerability in Linux USB-Audio driver
It provides information and tools to help organizations protect their networks from cyberattacks and respond to any attacks that may occur. It also informs the public about any vulnerabilities in widely used systems and applications.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Overall, CISA's role is vital to protecting the digital infrastructure of the US and other regions
Source: thehackernews.com
