Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Langflow CVE-2025-3248 Exploitation 2025: How Attackers Dumped AI…
Breach analysis Incident: 17 Jun 2025

Langflow CVE-2025-3248 Exploitation 2025: How Attackers Dumped AI Server Secrets and Built the Flodrix Botnet

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 10 min read
On this page

Langflow is a popular open-source tool for building AI agents and LLM workflows, and the servers that run it usually hold the API keys and database credentials those workflows need. CVE-2025-3248, a missing-authentication flaw rated CVSS 9.8, let anyone on the internet run Python code on a Langflow server through its code validation endpoint. Horizon3.ai reported it in February 2025, Langflow fixed it in version 1.3.0 on 31 March, and CISA listed it as actively exploited on 5 May. On 17 June 2025 Trend Micro reported an active campaign using the flaw to install Flodrix, a DDoS botnet. Before dropping the malware, the attackers ran reconnaissance commands, including one that dumps every environment variable, and sent the results to their command-and-control server. Trend Micro notes that environment variables can hold API keys, cloud credentials and database connection strings. Which secrets, if any, were taken from particular servers has not been reported.

Key takeaways

  • CVE-2025-3248 exposed Langflow's /api/v1/validate/code endpoint without authentication, so any visitor could run arbitrary Python code on the server. Versions before 1.3.0 are affected.
  • Trend Micro found attackers exploiting the flaw to deploy the Flodrix botnet, after running reconnaissance that included dumping all environment variables and sending the output to their command-and-control server.
  • Horizon3.ai counted more than 500 internet-exposed Langflow instances in April 2025; Censys put the figure at about 470 in May. No individual victim has been named.
  • This was exploitation in the wild, not just research: CISA added the CVE to its Known Exploited Vulnerabilities catalogue on 5 May 2025, and SANS honeypots saw scanning within two days of public exploits.
  • The identity lesson: an AI agent builder is a secrets store with a web interface, so an unauthenticated code endpoint hands over every key the agents use.

At a glance

OrganisationsLangflow (open-source AI agent and workflow builder backed by DataStax and IBM); operators of unpatched, internet-exposed Langflow servers
WhenReported to Langflow 22 February 2025; fixed 31 March 2025; exploitation confirmed by CISA 5 May 2025; Flodrix campaign reported 17 June 2025
AttackerUnattributed operators of the Flodrix botnet, which Trend Micro describes as an evolving variant of LeetHozer
Entry pointUnauthenticated remote code execution through Langflow's code validation endpoint (CVE-2025-3248)
Identities abusedSecrets in the Langflow server's environment, such as AI provider API keys, cloud credentials and database connection strings, dumped by the attackers' reconnaissance; the server's own compute, enlisted in a botnet
ImpactCompromised AI workflow servers turned into DDoS bots; environment secrets sent to attacker infrastructure; specific stolen credentials and victims not publicly reported
CategoryNHI, LLM / AI platform. Incident class: confirmed NHI breach (actively exploited flaw with environment secrets harvested by attackers; no named victims)

What happened

Langflow lets developers assemble AI agents and retrieval pipelines visually, connecting language models, vector databases and tools. Horizon3.ai described it as having "50K+ GitHub stars" and being backed by DataStax and IBM. To make those flows work, a Langflow server is configured with the credentials of every service it calls, typically as environment variables. Horizon3.ai found that the endpoint Langflow uses to check user-supplied code, /api/v1/validate/code, required no authentication and ran the code it was given. It reported the issue on 22 February 2025. The fix, which puts the endpoint behind authentication, shipped in Langflow 1.3.0 on 31 March, and the CVE was published on 7 April. When a third party published an exploit on 9 April, Horizon3.ai released its own write-up, noting "500+ exposed instances of Langflow on the Internet" according to Censys.

Exploitation followed quickly. Help Net Security reported on 6 May that CISA had added CVE-2025-3248 to its Known Exploited Vulnerabilities catalogue the day before. SANS Internet Storm Center honeypots had seen scans two days after the exploits were published, some trying to read a password file, from Tor exit nodes. Censys counted about 470 Langflow instances still exposed. Horizon3.ai advised isolating new AI tools in a private cloud or behind single sign-on rather than putting them straight on the internet.

On 17 June Trend Micro's researchers reported "an active campaign exploiting CVE-2025-3248 to deliver the Flodrix botnet". The attackers likely found targets through Shodan or FOFA, used a public proof of concept to get a shell, then ran reconnaissance and sent the output back to their server. The commands included whoami, reading the root user's shell history, network and SSH checks, and printenv, which Trend Micro describes simply: "Dumps all environment variables." It warns that this "can reveal sensitive information such as API keys, cloud credentials, database connection strings". The attackers then ran a downloader script that fetched Flodrix builds for several processor types. According to Trend Micro, quoted by The Hacker News, the attackers "use the vulnerability to execute downloader scripts on compromised Langflow servers." Flodrix hides itself, communicates over TCP and Tor, and launches several kinds of DDoS attack.

Neither Trend Micro nor later reporting names an affected organisation or confirms which secrets were collected from which servers. The Hacker News later added Censys research identifying 745 hosts compromised by the wider Flodrix operation, mostly in Taiwan and many of them internet cameras, which shows the botnet was not limited to Langflow.

Timeline

DateEvent
22 February 2025Horizon3.ai reports the unauthenticated code execution flaw to Langflow.
5 March 2025A fix is merged into the Langflow code base.
31 March 2025Langflow 1.3.0 is released with the fix.
7 April 2025CVE-2025-3248 is published.
9 April 2025A public exploit appears and Horizon3.ai publishes its analysis.
5 May 2025CISA adds CVE-2025-3248 to the Known Exploited Vulnerabilities catalogue.
6 May 2025Langflow 1.4.0 is released; Help Net Security reports active exploitation.
17 June 2025Trend Micro reports the Flodrix botnet campaign exploiting the flaw.

How it happened: the identity attack path

  1. Secrets concentrated on an AI server. Langflow servers hold the API keys and connection strings their agents and workflows need, commonly in environment variables.
  2. An endpoint with no identity check. The code validation endpoint accepted and executed Python from unauthenticated callers.
  3. Find exposed servers. Attackers likely used internet search engines such as Shodan or FOFA to locate unpatched Langflow instances.
  4. Dump the environment. Reconnaissance commands, including printenv, collected environment variables and system details and sent them to the attackers' server.
  5. Enlist the server. A downloader installed Flodrix, turning the compromised Langflow host into a DDoS bot.

Impact

  • Confirmed: active exploitation of CVE-2025-3248 in the wild (CISA, SANS, Trend Micro) and installation of Flodrix on compromised Langflow servers (Trend Micro).
  • Observed: attackers collecting environment variables and system information from compromised servers and sending them to command-and-control infrastructure, according to Trend Micro.
  • Potential: theft and reuse of AI provider API keys, cloud credentials and database connection strings held by Langflow servers. No specific stolen credential or victim has been reported.
  • Exposure: more than 500 internet-facing Langflow instances in April 2025 and about 470 in May, according to Censys figures cited by Horizon3.ai and Help Net Security.

What this means for NHI and AI agent security

AI agent builders are becoming one of the densest stores of non-human credentials in an organisation. A single Langflow deployment can hold keys for several model providers, vector databases, SaaS tools and cloud accounts, because each flow needs them to run. When the platform has an unauthenticated code path, every one of those identities is exposed at once, and the first thing a competent attacker does is dump the environment. The Flodrix operators wanted compute for DDoS, but the same access is worth more to someone who wants the keys, as the later JADEPUFFER agentic ransomware attack showed, when an AI agent exploited Langflow and harvested API keys and cloud credentials.

The pattern repeats across AI infrastructure. ShadowRay hit exposed Ray clusters in 2024 and Carbonato hunted AI API keys on exposed Docker hosts in 2026. AI tools are often deployed quickly by data teams, outside normal hardening, with long-lived keys in plain environment variables. Our AI Infrastructure Workload Identity Guide and LLMjacking Guide cover how to keep those credentials scoped, short-lived and out of reach.

Recommendations

  • Patch and take AI builders off the internet. Upgrade Langflow to 1.3.0 or later and place agent builders behind single sign-on or a private network, as Horizon3.ai advises. See our Shadow AI Discovery Guide.
  • Rotate every secret on an exposed server. If a Langflow instance ran a vulnerable version on the internet, assume its environment was read and rotate all keys and connection strings it held. See our Leaked Credential Response Playbook.
  • Move secrets out of environment variables. Fetch credentials at run time from a secrets manager with short-lived leases, so a process dump does not yield standing keys. See our Secrets Management Guide.
  • Scope AI provider keys tightly. Give each flow its own key with spending limits and only the models it needs, so a stolen key has limited value. See our LLMjacking Guide.
  • Monitor AI hosts for reconnaissance. Alert on shell commands such as printenv and whoami spawned by the Langflow process, and on outbound connections to unknown hosts.
  • Inventory AI tooling. Find Langflow, Ray, notebook and agent servers deployed outside standard change control. See our AI Infrastructure Workload Identity Guide.

Frequently asked questions

What is CVE-2025-3248 in Langflow?

CVE-2025-3248 is a critical flaw, rated CVSS 9.8, in Langflow versions before 1.3.0. The /api/v1/validate/code endpoint did not require authentication and executed the Python code it received, so anyone who could reach the server could run commands on it.

Was the Langflow vulnerability exploited?

Yes. CISA added it to its Known Exploited Vulnerabilities catalogue on 5 May 2025, and on 17 June 2025 Trend Micro reported attackers using it to install the Flodrix DDoS botnet after dumping environment variables and system information from compromised servers.

Were API keys stolen from Langflow servers?

Trend Micro observed attackers dumping all environment variables and sending them to their server, and warns that these can contain API keys, cloud credentials and database connection strings. No public report confirms which secrets were taken from specific servers, so any key on an exposed, unpatched server should be treated as compromised.

JADEPUFFER agentic ransomware 2026 · ShadowRay 2024 · Carbonato botnet 2026 · AI Infrastructure Workload Identity Guide · Secrets Management Guide

How NHI Mgmt Group can help

AI agent platforms collect API keys and service credentials faster than most security teams can track them. We help teams find where those non-human identities live, scope and rotate them, and keep AI tooling inside the same identity controls as the rest of the estate. See our NHI Foundation Level Training Course.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org