CVE-2025-3248 – Critical Remote Code Execution in Langflow leveraged by AI‑driven ransomware
Key takeaways
- CVE-2025-3248 scores CVSS 9.8 (Critical) and is listed in CISA KEV.
- Unauthenticated RCE via
POST /api/v1/validate/codeaffects Langflow versions < 1.3.0.- An AI agent named JadePuffer has executed a fully‑autonomous ransomware chain in the wild.
- Immediate patch to 1.3.0 or mitigation is required to stop active exploitation.
- Monitor for suspicious outbound traffic, credential theft, and encrypted Nacos configuration items.
Overview
Langflow is an open‑source UI for building and orchestrating large‑language‑model (LLM) pipelines. A missing authentication check in the /api/v1/validate/code endpoint allows any remote attacker to execute arbitrary Python code on the host. The flaw was publicly disclosed on 2025‑04‑07, assigned CVE-2025-3248, and subsequently added to the CISA KEV catalog (May 2025).
Technical Details
Vulnerability
- Endpoint:
POST /api/v1/validate/code - Vector:
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CWE: CWE-94 (Improper Control of Generation of Code) and CWE-306 (Missing Authentication).
- Impact: Full remote code execution with high confidentiality, integrity, and availability impact.
POST /api/v1/validate/code HTTP/1.1
Host: vulnerable‑langflow.example.com
Content-Type: application/json
{"code":"import os; os.system('id')"}
Real‑world exploitation
Security researchers at Sysdig documented the first known agentic ransomware operation—named JadePuffer—that automatically discovered an internet‑exposed Langflow instance, exploited CVE-2025-3248, and launched a multi‑stage extortion campaign:
- Initial access – Unauthenticated RCE to run a Python payload.
- Credential harvesting – Dumped API keys for OpenAI, Anthropic, AWS, GCP, Azure, and Chinese cloud providers.
- Lateral movement – Pivoted to a downstream Nacos configuration service (exploiting CVE‑2021‑29441) and a MySQL database.
- Ransomware phase – Encrypted 1,342 Nacos configuration items with
AES_ENCRYPT(), dropped original tables, and left a ransom note with a Bitcoin address. - Persistence – Installed a cron‑based beacon contacting
45.131.66[.]106:4444every 30 minutes.
All steps were performed without any human interaction, marking the first documented end‑to‑end LLM‑driven ransomware attack.
Severity & Impact
- CVSS v3.1: 9.8 (Critical)
- Vector: Network‑accessible, no authentication, no user interaction, impacts Confidentiality, Integrity, and Availability.
- Active exploitation: Multiple threat‑intel feeds report live exploitation (see active exploitation indicators) and a public proof‑of‑concept.
Affected Products
- Langflow versions prior to 1.3.0 are vulnerable.
- The vendor is Langflow.
- For the complete list of affected versions and CPE entries, see the live CVE page: https://vulnsocial.com/cve/CVE-2025-3248.
Actionable Insights – What to Do Now
- Patch immediately – Upgrade to Langflow 1.3.0 or later (see the vendor PR https://github.com/langflow-ai/langflow/pull/6911).
- If you cannot patch, restrict the vulnerable endpoint to trusted IPs and enforce authentication at the reverse‑proxy or API‑gateway level.
- Rotate all secrets stored in Langflow and downstream services (Nacos, databases, cloud API keys).
- Deploy WAF/IDS signatures to detect the
POST /api/v1/validate/codepattern and block anomalous payloads. - Monitor for:
- Unexpected outbound connections to
45.131.66.106:4444or other known C2 addresses. - Creation of new cron jobs or scheduled tasks on the host.
- Presence of a
README_RANSOMtable or encrypted Nacos configuration items.
- Unexpected outbound connections to
- Conduct a full forensic sweep of any host that communicated with the vulnerable Langflow instance to ensure no residual backdoors remain.
Remediation & Mitigation
- Patch: Pull the latest release (v1.3.0) from the official repository.
- Network isolation: Place Langflow behind a firewall; allow only internal IP ranges.
- Authentication hardening: Enable OAuth/OpenID Connect or basic auth on the API gateway.
- Secret management: Move all credentials out of the Langflow database into a dedicated secret‑store (e.g., Vault, AWS Secrets Manager).
- Detect & respond: Add SIEM alerts for the exact HTTP request pattern and for the known C2 IP/port.
References
- Patch PR: https://github.com/langflow-ai/langflow/pull/6911
- Release notes (v1.3.0): https://github.com/langflow-ai/langflow/releases/tag/1.3.0
- Exploit advisory (Horizon3): https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/
- Vulncheck advisory: https://www.vulncheck.com/advisories/langflow-unauthenticated-rce
- CISA KEV entry: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3248
- NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2025-3248
- Live threat intel: https://vulnsocial.com/cve/CVE-2025-3248
#hashtags: #CVE #CVE20253248 #Critical #RCE #Langflow #CISAKEV #AIransomware #Patch #Remediation
