Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Langflow-CVE-2025-3248-Multi-target — Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code. | Kitploit
Tools/GitHubGitHub/ill-deed/langflow-cve-2025-3248-multi-target
Vulnerability ScannersCode AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHubill-deed/langflow-cve-2025-3248-multi-target

Langflow-CVE-2025-3248-Multi-target

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

View Repository
191 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

⚠️ Langflow RCE Exploit Scanner (CVE-2025-3248)

This Python-based scanner automates the detection of unauthenticated Remote Code Execution (RCE) vulnerabilities in Langflow instances via CVE-2025-3248. It uses a proof-of-concept payload that abuses the /api/v1/validate/code endpoint to execute arbitrary shell commands.

🚨 CVE Details

  • CVE: CVE-2025-3248
  • Impact: Unauthenticated Remote Code Execution
  • Component: Langflow API (/api/v1/validate/code)
  • Exploit: Injection via dynamic code evaluation
  • Risk: Critical

🛠 Features

  • 🔎 Batch scan multiple targets from a file
  • ⚡️ Multi-threaded for fast performance
  • ✅ Validates RCE by checking for expected command output (e.g., uid=)
  • 📁 Outputs vulnerable targets to vuln.txt
  • 🧱 Clean, modular code structure

📦 Requirements

  • Python 3.x
  • requests library

Install dependencies:

pip install requests

📂 Usage

  1. Add targets (with or without http(s)://) to targets.txt, one per line:
http://example.com
192.168.1.100:7860
https://target.net
  1. Run the script:
python3 scanner.py
  1. Check vuln.txt for successful exploitation results:
http://vulnerable-target.com | uid=1000(user) gid=1000(user) groups=1000(user)

⚙️ Configuration

Modify the following values at the top of the script as needed:

COMMAND: Shell command to execute (default: id)

EXPECTED_SUBSTRING: Substring to confirm execution (default: uid=)

THREADS: Number of concurrent threads (default: 20)

🔒 Disclaimer

This tool is provided for educational and authorized security testing only. Unauthorized access to systems is illegal and unethical. You are solely responsible for your use of this code.

🙏 Credits

Exploit Author: ynsmroztas

Script Refactor: ill deed

📄 License

MIT License – use responsibly.

Download Tool