Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-23 · updated: 2026-09-23 · tags: [cve] · confidence: high · severity: critical · affected_sectors: [technology] · au_impact: false

CVE-2025-3248

Summary

A code-injection vulnerability in Langflow, the low-code framework for building LLM applications, scored CVSS 9.8 and in CISA's Known Exploited Vulnerabilities catalog since May 2025.

Details

The digest encountered the flaw as the access route rather than as a fresh advisory: ENCFORGE ransomware used CVE-2025-3248 as its entry point in July 2026 and then targeted AI model files rather than ordinary documents — a victim profile that follows directly from what the product is for, since Langflow deployments sit next to model weights, prompt stores and the credentials used to reach hosted inference APIs. The operational point for defenders is that an unauthenticated RCE on an AI tooling server is a route to both the model and the keys around it, so the KEV listing deserves the same remediation priority as any internet-facing web application.

Attribute Detail
CVE CVE-2025-3248
CVSS 9.8
Vendor / product Langflow (IBM)
Reported in the digest 2026-07-21

Related Pages

Sources: raw/digests/Cyber-Digest-2026-07-21.md