tag
Agentic-Ransomware
CVE-2025-3248
web
CRITICAL 9.8
KEV
Ransomware
EPSS 100%
Langflow Missing-Authentication Remote Code Execution (CVE-2025-3248)
CVE-2025-3248 is a missing-authentication vulnerability in Langflow's code-validation API. The /api/v1/validate/code endpoint accepts and executes arbitrary Python code submitted by any client, with no authentication check on the route, allowing an…
Patched
2026-07-03