module
Langflow AI RCE
| Disclosed | Created |
|---|---|
| Apr 9, 2025 | Apr 14, 2025 |
Disclosed
Apr 9, 2025
Created
Apr 14, 2025
Description
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint.
A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
Authors
Naveen Sunkavally (Horizon3.ai)
Takahiro Yokoyama
Takahiro Yokoyama
Platform
Python
Architectures
python
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.