POC of CVE-2025-3248
CVE-2025-3248-POC POC of CVE-2025-3248 usage: python pocpy 'xxxcom' 'ls /' leave some love on victims' computers pocpy
Code Injection Vulnerability in Langflow Versions Prior to 1.3.0
Langflow versions before 1.3.0 have a code injection vulnerability in the /api/v1/validate/code endpoint. This security issue allows a remote and unauthenticated attacker to send specially crafted HTTP requests that can execute arbitrary code on the system. The vulnerability poses a significant risk as it enables potential unauthorized code execution without requiring any prior authentication.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
langflow-ai langflow |
Critical Langflow RCE flaw exploited to hack AI app servers By Bill Toulas May 6, 2025 12:05 PM 0 The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has tagged a Langflow remote code execution vulnerability as actively exploited, urging organizations to apply security updates and mitigations as soon as possible. The vulnerability is tracked as CVE-2025-3248 and is a critical unauthenticated RCE flaw that allows any attacker on the internet to take full control of vulner...