References https://www.ithome.com.tw/news/168806 https://zhuanlan.zhihu.com/p/2036117482176500896 https://cloud.tencent.com/developer/article/2580276 https://www.trendmicro.com/zh_tw/research/25/f/langflow-vulnerability-flodric-botnet.html https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/Langflow%E6%A1%86%E6%9E%B6/Langflow%E6%A1%86%E6%9E%B6%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2025-3248).md https://www.ithome.com.tw/news/174608 https://zhuanlan.zhihu.com/p/2018334166954033325 https://www.obsidiansecurity.com/blog/cve-2025-34291-critical-account-takeover-and-rce-vulnerability-in-the-langflow-ai-agent-workflow-platform https://www.recordedfuture.com/blog/langflow-cve-2025-3248 https://www.darkreading.com/vulnerabilities-threats/easily-exploitable-langflow-vulnerability-patching https://www.zscaler.com/blogs/security-research/cve-2025-3248-rce-vulnerability-langflow https://www.scworld.com/news/critical-langflow-rce-vulnerability-exploited-within-20-hours https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx https://vulnerability.circl.lu/search?vendor=Langflow
Related VulnerabilitiesPoClangflow-api-exposure: Langflow - Unauthenticated API ExposurePoCCVE-2026-0768: Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_codeLangflow /api/v1/custom_component 代码执行漏洞(CVE-2024-37014)PoCCVE-2024-37014: Langflow <= 1.0.12 - Remote Code ExecutionIBM Langflow OSS 远程代码执行漏洞(CVE-2026-9198)PoCCVE-2026-55450: Langflow < 1.9.1 - Unauthenticated File UploadPoCCVE-2026-33497: Langflow < 1.7.0 - Path TraversalPoCCVE-2026-9198: IBM Langflow - Remote Code ExecutionLangflow build_public_tmp 代码执行漏洞(CVE-2026-33017)PoCCVE-2026-5027: Langflow <= 1.8.4 - Path Traversal to RCE via File UploadLangflow /api/v2/files 文件上传漏洞(CVE-2026-5027)Langflow /api/v1/validate/code 代码执行漏洞(CVE-2026-0770)PoCCVE-2026-33017: Langflow < 1.9.0 - Remote Code Execution