CyberSec.Space Logo
CVEブラウザに戻る

CVE-2025-3248

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score30.4180%
EPSS Percentile85.65th
Published2025-04-07
Last Modified2026-07-14
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

Affected Platforms (CPE)

📦
Langflow

Langflow

< 1.3.0

References & Advisories

関連するセキュリティ記事

関連する脆弱性情報