Langflow is a popular open-source tool for building AI agents and LLM workflows, and the servers that run it usually hold the API keys and database credentials those workflows need. CVE-2025-3248, a missing-authentication flaw rated CVSS 9.8, let anyone on the internet run Python code on a Langflow server through its code validation endpoint. Horizon3.ai reported it in February 2025, Langflow fixed it in version 1.3.0 on 31 March, and CISA listed it as actively exploited on 5 May. On 17 June 2025 Trend Micro reported an active campaign using the flaw to install Flodrix, a DDoS botnet. Before dropping the malware, the attackers ran reconnaissance commands, including one that dumps every environment variable, and sent the results to their command-and-control server. Trend Micro notes that environment variables can hold API keys, cloud credentials and database connection strings. Which secrets, if any, were taken from particular servers has not been reported.
Key takeaways
- CVE-2025-3248 exposed Langflow's
/api/v1/validate/codeendpoint without authentication, so any visitor could run arbitrary Python code on the server. Versions before 1.3.0 are affected. - Trend Micro found attackers exploiting the flaw to deploy the Flodrix botnet, after running reconnaissance that included dumping all environment variables and sending the output to their command-and-control server.
- Horizon3.ai counted more than 500 internet-exposed Langflow instances in April 2025; Censys put the figure at about 470 in May. No individual victim has been named.
- This was exploitation in the wild, not just research: CISA added the CVE to its Known Exploited Vulnerabilities catalogue on 5 May 2025, and SANS honeypots saw scanning within two days of public exploits.
- The identity lesson: an AI agent builder is a secrets store with a web interface, so an unauthenticated code endpoint hands over every key the agents use.
At a glance
| Organisations | Langflow (open-source AI agent and workflow builder backed by DataStax and IBM); operators of unpatched, internet-exposed Langflow servers |
|---|---|
| When | Reported to Langflow 22 February 2025; fixed 31 March 2025; exploitation confirmed by CISA 5 May 2025; Flodrix campaign reported 17 June 2025 |
| Attacker | Unattributed operators of the Flodrix botnet, which Trend Micro describes as an evolving variant of LeetHozer |
| Entry point | Unauthenticated remote code execution through Langflow's code validation endpoint (CVE-2025-3248) |
| Identities abused | Secrets in the Langflow server's environment, such as AI provider API keys, cloud credentials and database connection strings, dumped by the attackers' reconnaissance; the server's own compute, enlisted in a botnet |
| Impact | Compromised AI workflow servers turned into DDoS bots; environment secrets sent to attacker infrastructure; specific stolen credentials and victims not publicly reported |
| Category | NHI, LLM / AI platform. Incident class: confirmed NHI breach (actively exploited flaw with environment secrets harvested by attackers; no named victims) |
What happened
Langflow lets developers assemble AI agents and retrieval pipelines visually, connecting language models, vector databases and tools. Horizon3.ai described it as having "50K+ GitHub stars" and being backed by DataStax and IBM. To make those flows work, a Langflow server is configured with the credentials of every service it calls, typically as environment variables. Horizon3.ai found that the endpoint Langflow uses to check user-supplied code, /api/v1/validate/code, required no authentication and ran the code it was given. It reported the issue on 22 February 2025. The fix, which puts the endpoint behind authentication, shipped in Langflow 1.3.0 on 31 March, and the CVE was published on 7 April. When a third party published an exploit on 9 April, Horizon3.ai released its own write-up, noting "500+ exposed instances of Langflow on the Internet" according to Censys.
Exploitation followed quickly. Help Net Security reported on 6 May that CISA had added CVE-2025-3248 to its Known Exploited Vulnerabilities catalogue the day before. SANS Internet Storm Center honeypots had seen scans two days after the exploits were published, some trying to read a password file, from Tor exit nodes. Censys counted about 470 Langflow instances still exposed. Horizon3.ai advised isolating new AI tools in a private cloud or behind single sign-on rather than putting them straight on the internet.
On 17 June Trend Micro's researchers reported "an active campaign exploiting CVE-2025-3248 to deliver the Flodrix botnet". The attackers likely found targets through Shodan or FOFA, used a public proof of concept to get a shell, then ran reconnaissance and sent the output back to their server. The commands included whoami, reading the root user's shell history, network and SSH checks, and printenv, which Trend Micro describes simply: "Dumps all environment variables." It warns that this "can reveal sensitive information such as API keys, cloud credentials, database connection strings". The attackers then ran a downloader script that fetched Flodrix builds for several processor types. According to Trend Micro, quoted by The Hacker News, the attackers "use the vulnerability to execute downloader scripts on compromised Langflow servers." Flodrix hides itself, communicates over TCP and Tor, and launches several kinds of DDoS attack.
Neither Trend Micro nor later reporting names an affected organisation or confirms which secrets were collected from which servers. The Hacker News later added Censys research identifying 745 hosts compromised by the wider Flodrix operation, mostly in Taiwan and many of them internet cameras, which shows the botnet was not limited to Langflow.
Timeline
| Date | Event |
|---|---|
| 22 February 2025 | Horizon3.ai reports the unauthenticated code execution flaw to Langflow. |
| 5 March 2025 | A fix is merged into the Langflow code base. |
| 31 March 2025 | Langflow 1.3.0 is released with the fix. |
| 7 April 2025 | CVE-2025-3248 is published. |
| 9 April 2025 | A public exploit appears and Horizon3.ai publishes its analysis. |
| 5 May 2025 | CISA adds CVE-2025-3248 to the Known Exploited Vulnerabilities catalogue. |
| 6 May 2025 | Langflow 1.4.0 is released; Help Net Security reports active exploitation. |
| 17 June 2025 | Trend Micro reports the Flodrix botnet campaign exploiting the flaw. |
How it happened: the identity attack path
- Secrets concentrated on an AI server. Langflow servers hold the API keys and connection strings their agents and workflows need, commonly in environment variables.
- An endpoint with no identity check. The code validation endpoint accepted and executed Python from unauthenticated callers.
- Find exposed servers. Attackers likely used internet search engines such as Shodan or FOFA to locate unpatched Langflow instances.
- Dump the environment. Reconnaissance commands, including
printenv, collected environment variables and system details and sent them to the attackers' server. - Enlist the server. A downloader installed Flodrix, turning the compromised Langflow host into a DDoS bot.
Impact
- Confirmed: active exploitation of CVE-2025-3248 in the wild (CISA, SANS, Trend Micro) and installation of Flodrix on compromised Langflow servers (Trend Micro).
- Observed: attackers collecting environment variables and system information from compromised servers and sending them to command-and-control infrastructure, according to Trend Micro.
- Potential: theft and reuse of AI provider API keys, cloud credentials and database connection strings held by Langflow servers. No specific stolen credential or victim has been reported.
- Exposure: more than 500 internet-facing Langflow instances in April 2025 and about 470 in May, according to Censys figures cited by Horizon3.ai and Help Net Security.
What this means for NHI and AI agent security
AI agent builders are becoming one of the densest stores of non-human credentials in an organisation. A single Langflow deployment can hold keys for several model providers, vector databases, SaaS tools and cloud accounts, because each flow needs them to run. When the platform has an unauthenticated code path, every one of those identities is exposed at once, and the first thing a competent attacker does is dump the environment. The Flodrix operators wanted compute for DDoS, but the same access is worth more to someone who wants the keys, as the later JADEPUFFER agentic ransomware attack showed, when an AI agent exploited Langflow and harvested API keys and cloud credentials.
The pattern repeats across AI infrastructure. ShadowRay hit exposed Ray clusters in 2024 and Carbonato hunted AI API keys on exposed Docker hosts in 2026. AI tools are often deployed quickly by data teams, outside normal hardening, with long-lived keys in plain environment variables. Our AI Infrastructure Workload Identity Guide and LLMjacking Guide cover how to keep those credentials scoped, short-lived and out of reach.
Recommendations
- Patch and take AI builders off the internet. Upgrade Langflow to 1.3.0 or later and place agent builders behind single sign-on or a private network, as Horizon3.ai advises. See our Shadow AI Discovery Guide.
- Rotate every secret on an exposed server. If a Langflow instance ran a vulnerable version on the internet, assume its environment was read and rotate all keys and connection strings it held. See our Leaked Credential Response Playbook.
- Move secrets out of environment variables. Fetch credentials at run time from a secrets manager with short-lived leases, so a process dump does not yield standing keys. See our Secrets Management Guide.
- Scope AI provider keys tightly. Give each flow its own key with spending limits and only the models it needs, so a stolen key has limited value. See our LLMjacking Guide.
- Monitor AI hosts for reconnaissance. Alert on shell commands such as
printenvandwhoamispawned by the Langflow process, and on outbound connections to unknown hosts. - Inventory AI tooling. Find Langflow, Ray, notebook and agent servers deployed outside standard change control. See our AI Infrastructure Workload Identity Guide.
Frequently asked questions
What is CVE-2025-3248 in Langflow?
CVE-2025-3248 is a critical flaw, rated CVSS 9.8, in Langflow versions before 1.3.0. The /api/v1/validate/code endpoint did not require authentication and executed the Python code it received, so anyone who could reach the server could run commands on it.
Was the Langflow vulnerability exploited?
Yes. CISA added it to its Known Exploited Vulnerabilities catalogue on 5 May 2025, and on 17 June 2025 Trend Micro reported attackers using it to install the Flodrix DDoS botnet after dumping environment variables and system information from compromised servers.
Were API keys stolen from Langflow servers?
Trend Micro observed attackers dumping all environment variables and sending them to their server, and warns that these can contain API keys, cloud credentials and database connection strings. No public report confirms which secrets were taken from specific servers, so any key on an exposed, unpatched server should be treated as compromised.
Related NHI Mgmt Group resources
JADEPUFFER agentic ransomware 2026 · ShadowRay 2024 · Carbonato botnet 2026 · AI Infrastructure Workload Identity Guide · Secrets Management Guide
How NHI Mgmt Group can help
AI agent platforms collect API keys and service credentials faster than most security teams can track them. We help teams find where those non-human identities live, scope and rotate them, and keep AI tooling inside the same identity controls as the rest of the estate. See our NHI Foundation Level Training Course.
References
- Horizon3.ai: Unsafe at Any Speed: Abusing Python Exec for Unauth RCE in Langflow AI (9 April 2025)
- Help Net Security: RCE flaw in tool for building AI agents exploited by attackers (CVE-2025-3248) (6 May 2025)
- Trend Micro: Critical Langflow Vulnerability (CVE-2025-3248) Actively Exploited to Deliver Flodrix Botnet (17 June 2025)
- The Hacker News: New Flodrix Botnet Variant Exploits Langflow AI Server RCE Bug to Launch DDoS Attacks (17 June 2025)