CVE-2025-3248 — exploited in the wild
Exploitation observed by OffSeq honeypot sensors · last 30 days · last seen 1 day ago · first observed 2026-08-20 (25 days ago)
226
Exploitation attempts
33
Distinct source IPs
9.8
CVSS
KEV
CISA Known-Exploited
Listed in CISA's Known Exploited Vulnerabilities catalog and still under active attack against OffSeq honeypot decoys.
About CVE-2025-3248
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
CWE-306CWE-94
OffSeq's global honeypot fleet recorded 226 exploitation attempts against CVE-2025-3248 from 33 distinct source IPs in the last 30 days — direct in-the-wild telemetry: every hit is a real attacker probing a decoy, not a scan of a vulnerability database.
Top attacking countries
- France207
- United States14
- Belgium5