Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Playstation’s dualsense edge wireless controller is on sale for a record-cum price

    June 8, 2025

    Remove project directors presented as malicious NPM package utilities

    June 8, 2025

    This new Android 16 feature brings real -time rain to your phone

    June 8, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Exploitation of Critical Langflow RCE Dosha to hack AI app server
    Security

    Exploitation of Critical Langflow RCE Dosha to hack AI app server

    PineapplesUpdateBy PineapplesUpdateMay 7, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Exploitation of Critical Langflow RCE Dosha to hack AI app server
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Exploitation of Critical Langflow RCE Dosha to hack AI app server

    The US Cyber ​​Security and Infrastructure Security Agency (CISA) has actively tagged a language remote code execution vulnerability, urged organizations to implement security updates and laxity as soon as possible.

    The vulnerability has been tracked as the CVE-2025-3248 and is an important informal RCE defect that allows any attacker to take full control of the weak language by exploiting the API andpoint defect on the Internet.

    LLM-SUS Visual Programming Tools for the construction of LLM-operated workflow using Langflow Langchen components. It provides a drag-end-drag interface to make, test and deploy AI agents or pipelines without writing full backnd code.

    Tools, which are on about 60k stars and 6.3k thorns on github, are used by AI developers, researchers and startups, prototype chatbots, data pipelines, agent systems and AI applications.

    The Langflow exposes an endpoint (/api/V1/validate/code) designed to validate the user-produced code. In weak versions, this endpoint does not safely sandbox or does not clean the input, allowing an attacker to send malicious code to the endpoint and execute it directly on the server.

    CVE-2025-3248 was fixed Version 1.3.0It was released on 1 April 2025, so it is recommended to upgrade in that version or reduce the risks arising from subsequent defects.

    Was the patch MinimumJust add authentication to the weak closing point, including no sandboxing or strict.

    Latest Langflow version, 1.4.0Today was released earlier and includes a long list of fixes, so users should upgrade this release.

    Horizon 3 researchers published one Intensive technical blog Regarding the defect on 9 April 2025, including a proof-of-concept exploitation.

    Researchers warned of the high probability of exploitation of CVE-2025–3248, at that time identified at least 500 Internet-desired examples.

    POC exploitation of horizon 3 in action
    POC exploitation of horizon 3 in action
    Source: Horizon 3

    Those who cannot immediately upgrade to a safe version are recommended to restrict network access to the language by putting firewalls, certified reverse proxy, or VPN behind. In addition, direct internet exposure is discouraged.

    Sisa is Gave to federal agencies By May 26, 2025, to apply security updates or mitigations or stop using software.

    CISA has not celebrated any specific details about exploitation activity and said it is unknown at present whether ransomware groups are exploiting vulnerability.

    For Langflow users, it is important to take into account the comments of the horizon 3 about the design of the tool, which, according to them, there is poor privilege separation, no sandbox, and the history of RCES stems from its nature and intended functionality.

    CVE-2025–3248 Langflow is the first true uncontrolled RCE defect, and immediate action is required, given the state of its active exploitation.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    app Critical Dosha exploitation hack Langflow RCE server
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHorticulture proceeds for homagers: Today’s mortgage rate on May 7, 2025
    Next Article Best iPad for 2025: How to choose the best Apple Tablet for you
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Remove project directors presented as malicious NPM package utilities

    June 8, 2025
    Security

    Supply series attacks Glustac NPM package with 960K weekly download

    June 7, 2025
    How-To

    iPhone users say that mail app is suddenly cold with iOS 18.5 – here a fix you can try

    June 7, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025591 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025534 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025462 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Microsoft confirms Windows 10 update Bitlocker can trigger recovery

    May 16, 20250 Views

    Huawei Watch Fit 4 Pro Review: This is great, provided you can get one thing

    May 16, 20250 Views

    Robot Video: Battlefield Triages, Firefighting Drone, and more

    May 16, 20250 Views
    Our Picks

    Playstation’s dualsense edge wireless controller is on sale for a record-cum price

    June 8, 2025

    Remove project directors presented as malicious NPM package utilities

    June 8, 2025

    This new Android 16 feature brings real -time rain to your phone

    June 8, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.