
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
This Python-based scanner automates the detection of unauthenticated Remote Code Execution (RCE) vulnerabilities in Langflow instances via CVE-2025-3248. It uses a proof-of-concept payload that abuses the /api/v1/validate/code endpoint to execute arbitrary shell commands.
/api/v1/validate/code)uid=)vuln.txtrequests libraryInstall dependencies:
pip install requests
http://example.com
192.168.1.100:7860
https://target.net
python3 scanner.py
http://vulnerable-target.com | uid=1000(user) gid=1000(user) groups=1000(user)
Modify the following values at the top of the script as needed:
COMMAND: Shell command to execute (default: id)
EXPECTED_SUBSTRING: Substring to confirm execution (default: uid=)
THREADS: Number of concurrent threads (default: 20)
This tool is provided for educational and authorized security testing only. Unauthorized access to systems is illegal and unethical. You are solely responsible for your use of this code.
Exploit Author: ynsmroztas
Script Refactor: ill deed
MIT License – use responsibly.