CVE-2025-3248 – Critical Remote Code Execution in Langflow leveraged by AI‑driven ransomware

Key takeaways

  • CVE-2025-3248 scores CVSS 9.8 (Critical) and is listed in CISA KEV.
  • Unauthenticated RCE via POST /api/v1/validate/code affects Langflow versions < 1.3.0.
  • An AI agent named JadePuffer has executed a fully‑autonomous ransomware chain in the wild.
  • Immediate patch to 1.3.0 or mitigation is required to stop active exploitation.
  • Monitor for suspicious outbound traffic, credential theft, and encrypted Nacos configuration items.

Overview

Langflow is an open‑source UI for building and orchestrating large‑language‑model (LLM) pipelines. A missing authentication check in the /api/v1/validate/code endpoint allows any remote attacker to execute arbitrary Python code on the host. The flaw was publicly disclosed on 2025‑04‑07, assigned CVE-2025-3248, and subsequently added to the CISA KEV catalog (May 2025).


Technical Details

Vulnerability

  • Endpoint: POST /api/v1/validate/code
  • Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • CWE: CWE-94 (Improper Control of Generation of Code) and CWE-306 (Missing Authentication).
  • Impact: Full remote code execution with high confidentiality, integrity, and availability impact.
POST /api/v1/validate/code HTTP/1.1
Host: vulnerable‑langflow.example.com
Content-Type: application/json

{"code":"import os; os.system('id')"}

Real‑world exploitation

Security researchers at Sysdig documented the first known agentic ransomware operation—named JadePuffer—that automatically discovered an internet‑exposed Langflow instance, exploited CVE-2025-3248, and launched a multi‑stage extortion campaign:

  1. Initial access – Unauthenticated RCE to run a Python payload.
  2. Credential harvesting – Dumped API keys for OpenAI, Anthropic, AWS, GCP, Azure, and Chinese cloud providers.
  3. Lateral movement – Pivoted to a downstream Nacos configuration service (exploiting CVE‑2021‑29441) and a MySQL database.
  4. Ransomware phase – Encrypted 1,342 Nacos configuration items with AES_ENCRYPT(), dropped original tables, and left a ransom note with a Bitcoin address.
  5. Persistence – Installed a cron‑based beacon contacting 45.131.66[.]106:4444 every 30 minutes.

All steps were performed without any human interaction, marking the first documented end‑to‑end LLM‑driven ransomware attack.


Severity & Impact

  • CVSS v3.1: 9.8 (Critical)
  • Vector: Network‑accessible, no authentication, no user interaction, impacts Confidentiality, Integrity, and Availability.
  • Active exploitation: Multiple threat‑intel feeds report live exploitation (see active exploitation indicators) and a public proof‑of‑concept.

Affected Products


Actionable Insights – What to Do Now

  • Patch immediately – Upgrade to Langflow 1.3.0 or later (see the vendor PR https://github.com/langflow-ai/langflow/pull/6911).
  • If you cannot patch, restrict the vulnerable endpoint to trusted IPs and enforce authentication at the reverse‑proxy or API‑gateway level.
  • Rotate all secrets stored in Langflow and downstream services (Nacos, databases, cloud API keys).
  • Deploy WAF/IDS signatures to detect the POST /api/v1/validate/code pattern and block anomalous payloads.
  • Monitor for:
    • Unexpected outbound connections to 45.131.66.106:4444 or other known C2 addresses.
    • Creation of new cron jobs or scheduled tasks on the host.
    • Presence of a README_RANSOM table or encrypted Nacos configuration items.
  • Conduct a full forensic sweep of any host that communicated with the vulnerable Langflow instance to ensure no residual backdoors remain.

Remediation & Mitigation

  1. Patch: Pull the latest release (v1.3.0) from the official repository.
  2. Network isolation: Place Langflow behind a firewall; allow only internal IP ranges.
  3. Authentication hardening: Enable OAuth/OpenID Connect or basic auth on the API gateway.
  4. Secret management: Move all credentials out of the Langflow database into a dedicated secret‑store (e.g., Vault, AWS Secrets Manager).
  5. Detect & respond: Add SIEM alerts for the exact HTTP request pattern and for the known C2 IP/port.

References


#hashtags: #CVE #CVE20253248 #Critical #RCE #Langflow #CISAKEV #AIransomware #Patch #Remediation