CVE-2025-3248 | langflow-ai langflow up to 1.2.0 HTTP Request /api/v1/validate/code missing authentication (EUVD-2025-10011 / EDB-52262)
A vulnerability was found in langflow-ai langflow up to 1.2.0. It has been declared as critical. This impacts an unknown function of the file /api/v1/validate/code of the component HTTP Request Handler. The manipulation results in missing authentication.
This vulnerability was named CVE-2025-3248. The attack may be performed from remote. In addition, an exploit is available.
It is recommended to upgrade the affected component.