MIRAGE
Threat IntelligenceCVEs › CVE-2025-3248

CVE-2025-3248 — exploited in the wild

Exploitation observed by OffSeq honeypot sensors · last 30 days · last seen 1 day ago · first observed 2026-08-20 (25 days ago)

226
Exploitation attempts
33
Distinct source IPs
9.8
CVSS
KEV
CISA Known-Exploited

Listed in CISA's Known Exploited Vulnerabilities catalog and still under active attack against OffSeq honeypot decoys.

About CVE-2025-3248

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

CWE-306CWE-94

OffSeq's global honeypot fleet recorded 226 exploitation attempts against CVE-2025-3248 from 33 distinct source IPs in the last 30 days — direct in-the-wild telemetry: every hit is a real attacker probing a decoy, not a scan of a vulnerability database.

Top attacking countries

Top attacking networks

Techniques observed

Open the live CVE-2025-3248 view →

References