Vulnerabilities
Vulnerable Software
Langflow:  >> Langflow  >> 1.1.0  Security Vulnerabilities
Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an authenticated user with RCE access can invoke the internal CLI command langflow superuser to create a new administrative user. This results in full superuser access, even if the user initially registered through the UI as a regular (non-admin) account. A patched version has not been made public at this time.
CVSS Score
8.8
EPSS Score
0.0
Published
2025-08-25
CVE-2025-3248
Known exploited
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
CVSS Score
9.8
EPSS Score
0.92
Published
2025-04-07


Contact Us

Shodan ® - All rights reserved