A newly discovered security vulnerability, CVE-2025-3248, has been identified in Langflow, a popular tool used for building agentic AI workflows. This vulnerability poses a severe risk, allowing attackers to gain full control of vulnerable servers without needing authentication.
The issue has been patched in Langflow 1.3.0, and all users are strongly advised to upgrade immediately to protect their environments.
Recommended mitigations are to update to Langflow versions 1.3.0, or restrict network access to it.
The NodeZero® platform empowers your organization to reduce your security risks by autonomously finding exploitable weaknesses in your network, giving you detailed guidance around how to priortize and fix them, and having you immediately verify that your fixes are effective.