Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Exploitation of Critical Langflow RCE Dosha to hack AI app server
    Security

    Exploitation of Critical Langflow RCE Dosha to hack AI app server

    PineapplesUpdateBy PineapplesUpdateMay 7, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Exploitation of Critical Langflow RCE Dosha to hack AI app server
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Exploitation of Critical Langflow RCE Dosha to hack AI app server

    The US Cyber ​​Security and Infrastructure Security Agency (CISA) has actively tagged a language remote code execution vulnerability, urged organizations to implement security updates and laxity as soon as possible.

    The vulnerability has been tracked as the CVE-2025-3248 and is an important informal RCE defect that allows any attacker to take full control of the weak language by exploiting the API andpoint defect on the Internet.

    LLM-SUS Visual Programming Tools for the construction of LLM-operated workflow using Langflow Langchen components. It provides a drag-end-drag interface to make, test and deploy AI agents or pipelines without writing full backnd code.

    Tools, which are on about 60k stars and 6.3k thorns on github, are used by AI developers, researchers and startups, prototype chatbots, data pipelines, agent systems and AI applications.

    The Langflow exposes an endpoint (/api/V1/validate/code) designed to validate the user-produced code. In weak versions, this endpoint does not safely sandbox or does not clean the input, allowing an attacker to send malicious code to the endpoint and execute it directly on the server.

    CVE-2025-3248 was fixed Version 1.3.0It was released on 1 April 2025, so it is recommended to upgrade in that version or reduce the risks arising from subsequent defects.

    Was the patch MinimumJust add authentication to the weak closing point, including no sandboxing or strict.

    Latest Langflow version, 1.4.0Today was released earlier and includes a long list of fixes, so users should upgrade this release.

    Horizon 3 researchers published one Intensive technical blog Regarding the defect on 9 April 2025, including a proof-of-concept exploitation.

    Researchers warned of the high probability of exploitation of CVE-2025–3248, at that time identified at least 500 Internet-desired examples.

    POC exploitation of horizon 3 in action
    POC exploitation of horizon 3 in action
    Source: Horizon 3

    Those who cannot immediately upgrade to a safe version are recommended to restrict network access to the language by putting firewalls, certified reverse proxy, or VPN behind. In addition, direct internet exposure is discouraged.

    Sisa is Gave to federal agencies By May 26, 2025, to apply security updates or mitigations or stop using software.

    CISA has not celebrated any specific details about exploitation activity and said it is unknown at present whether ransomware groups are exploiting vulnerability.

    For Langflow users, it is important to take into account the comments of the horizon 3 about the design of the tool, which, according to them, there is poor privilege separation, no sandbox, and the history of RCES stems from its nature and intended functionality.

    CVE-2025–3248 Langflow is the first true uncontrolled RCE defect, and immediate action is required, given the state of its active exploitation.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    app Critical Dosha exploitation hack Langflow RCE server
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHorticulture proceeds for homagers: Today’s mortgage rate on May 7, 2025
    Next Article Best iPad for 2025: How to choose the best Apple Tablet for you
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    No matter? No problem! Imagine a smart home app to control all your devices

    January 14, 2026
    Startups

    Do you work with multiple browsers? You’ll love this free MacOS app – see why

    January 6, 2026
    Startups

    This new Linux desktop runs like an app on your existing desktop – and I highly recommend it

    January 1, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.