HomeSecurityLangflow vulnerability exploited by Flodrix Botnet

Langflow vulnerability exploited by Flodrix Botnet

Cybercriminals have begun exploiting a recently patched vulnerability in Langflow to join devices in the Flodrix botnet, Trend Micro warned on Tuesday.

See also: New Mirai botnet infects TBK DVR devices via vulnerability

Flodrix Botnet

The vulnerability, listed as CVE-2025-3248 , began to become widely known in early May, after it was added to the US cybersecurity agency CISA's Known Exploited Vulnerabilities (KEV) list

The vulnerability, which can be exploited by a remote and unauthenticated attacker to execute arbitrary code, was first disclosed in early April when an update was released with Langflow version 1.3.0. About a week later, technical details and proof-of-concept (PoC) exploits began to emerge.

Langflow is a popular platform designed for building and deploying AI agents and workflows. It has over 70,000 stars on GitHub.

When CISA added the CVE-2025-3248 vulnerability to the KEV list, there was no information yet available about attacks exploiting it.

See also: FBI: BADBOX 2.0 botnet has infected millions of devices

Trend Micro has now revealed that the vulnerability has been exploited in attacks by the Flodrix botnet. Specifically, the attackers scanned the internet for vulnerable installations of Langflow and used one of the available proof-of-concept (PoC) exploits to gain access to the system and execute various reconnaissance commands.

Langflow vulnerability exploited by Flodrix Botnet

The attacker then downloaded and executed the Flodrix malware on the compromised systems. Once activated, the malware establishes a connection to the command and control (C&C) server and awaits instructions from its operator.

The Flodrix botnet is primarily used to carry out DDoS attacks. According to Trend Micro, the malware used in these attacks is an evolution of LeetHozer, which was analyzed in 2020 by Chinese cybersecurity company Qihoo 360.

Currently, the Censys search engine shows over 1,600 instances of Langflow exposed online, but it is not clear how many of them are actually vulnerable to attacks.

See also: AyySSHush Botnet hacked 9,000+ ASUS routers

Based on the above information, it is clear that the CVE-2025-3248 vulnerability in Langflow poses a serious threat to the security of systems using the platform. Given that Langflow is widely used in the development of artificial intelligence applications, with thousands of installations exposed online, the rapid exploitation of the vulnerability by cybercriminals highlights the importance of promptly applying security updates.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS