Outbreak Alert Langflow Unauth RCE Attack Released: May 15, 2025 Updated: Jul 06, 2026 Download PDF » Share Langflow Unauth RCE Attack Tags High Severity Watch Video Langflow Unauth RCE Attack Video Share Subscribe Overview Analysis Solutions Threat Intelligence References Subscribe Overview Analysis Solutions Threat Intelligence References AI builder for agentic applications targeted FortiGuard Labs has observed a significant uptick in attacks targeting Langflow, leveraging a recently discovered authentication bypass vulnerability that allows unauthenticated remote attackers to fully compromise affected servers. Learn More » Common Vulnerabilities and Exposures CVE-2025-3248 Background Langflow is a Python-based web application that offers a visual interface for building AI-driven agents and workflows. A critical authentication bypass vulnerability, identified as CVE-2025-3248, has been discovered in Langflow. This vulnerability allows remote, unauthenticated attackers to execute arbitrary code on affected instances by sending a specially crafted HTTP request with a malicious payload. As AI workflows become increasingly prevalent across industries, the need to ensure the security of AI tools and applications has never been more critical. With the growing reliance on AI systems for decision-making, automation, and innovation, any vulnerability or breach in these systems could have far-reaching consequences. Explore the current challenges, and discover how FortiAI seamlessly integrates security and transformation to safeguard your AI-driven operations. https://www.fortinet.com/solutions/enterprise-midsize-business/fortiai Click here to analyze the Real-Time Threat Map Latest Development Recent news and incidents related to cybersecurity threats encompassing various events such as data breaches, cyber-attacks, security incidents, and vulnerabilities discovered. Organizations using Langflow in their AI development workflows are advised to upgrade to version 1.3.0. July 01, 2026: ecent research from Sysdig documents the JADEPUFFER campaign, in which attackers exploited the Langflow unauthenticated RCE vulnerability (CVE-2025-3248) as the initial access vector for a fully automated, AI-assisted ransomware operation. https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion June 17, 2025: Trend Research has identified an active campaign exploiting CVE-2025-3248 to deliver the Flodrix botnet. https://www.trendmicro.com/en_us/research/25/f/langflow-vulnerability-flodric-botnet.html# May 06, 2025: FortiGuard Threat Signal Report released- Langflow Missing Authentication Vulnerability https://www.fortiguard.com/threat-signal-report/6085/langflow-missing-authentication-vulnerability May 05, 2025: The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that this vulnerability is actively being exploited in the wild. As a result, it has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, emphasizing the urgent need for organizations using Langflow to take immediate action to mitigate this security risk. April 09, 2025: Horizon3.ai released a detailed blog post. https://horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/ March 31, 2025: Langflow 1.3.0 released https://github.com/langflow-ai/langflow/releases/tag/1.3.0 FortiGuard Cybersecurity Framework Mitigate security threats and vulnerabilities by leveraging the range of FortiGuard Services. PROTECT Lure Decoy VM IPS Web App Security DETECT IOC Outbreak Detection Content Update RESPOND Automated Response Assisted Response Services RECOVER NOC/SOC Training End-User Training IDENTIFY Vulnerability Management Attack Surface Monitoring (Inside & Outside) Attack Surface Hardening Lure FortiDeceptor Decoy VM FortiDeceptor IPS Detects and blocks attack attempts leveraging the vulnerability FortiADC DB 32.009 FortiGate DB 32.009 FortiNDR DB 32.009 FortiNDR Cloud DB 32.009 FortiProxy DB 32.009 FortiSASE DB 32.009 Web App Security Detects and blocks attack attempts leveraging the vulnerability FortiADC DB 1.00064 FortiWeb DB 0.00403 IOC FortiAnalyzer FortiCloud SOCaaS FortiSIEM FortiSOAR Outbreak Detection FortiAnalyzer DB 2.00073 FortiNDR Cloud FortiSIEM DB 805 FortiSOAR Content Update FortiSIEM Automated Response Services that can automaticlly respond to this outbreak. FortiXDR Assisted Response Services Experts to assist you with analysis, containment and response activities. Incident Response NOC/SOC Training Train your network and security professionals and optimize your incident response to stay on top of the cyberattacks. NSE Training Response Readiness End-User Training Raise security awareness to your employees that are continuously being targeted by phishing, drive-by download and other forms of cyberattacks. Security Awareness & Training Vulnerability Management Detects end-user devices running the vulnerable application. FortiDevSec Attack Surface Monitoring (Inside & Outside) FortiRecon: ACI FortiRecon: EASM Attack Surface Hardening Check Security Fabric devices to build actionable configuration recommendations and key indicators. Security Rating Threat Intelligence Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities. ✖ References Sources of information in support and relation to this Outbreak and vendor. FortiGuard Threat Signal Report Learn More » Langflow 1.3.0 Release Learn More » Horizon3.ai Post Learn More » FortiGuard AI-Protect Security Services Learn More » FortiAI Learn More » About FortiGuard Outbreak Alerts Learn More »
A critical authentication bypass vulnerability in Langflow (CVE-2025-3248, CVSS 9.8) allows unauthenticated remote code execution via a specially crafted HTTP request. The vulnerability affects Langflow versions prior to 1.3.0, and organizations must upgrade to version 1.3.0 to remediate it. This flaw is actively exploited in the wild as an initial access vector for ransomware and botnet campaigns.