Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence

May 6, 2025

A recently disclosed critical security flaw impacting the open-source Langflow platform has been added to the Known Exploited Vulnerabilities (KEV) catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), citing evidence of active exploitation.
The vulnerability, tracked as CVE-2025-3248, carries a CVSS score of 9.8 out of a maximum of 10.0.
“Langflow contains a missing

Get Free Report & Network Analysis

Please check your email for the free report.