Vulnerabilities & Exploits

Langflow Intrusion Now Targets the Model Itself

Once an attacker has Langflow, cleaning the app does not protect the AI system anymore. JADEPUFFER has shifted from improvised destruction to ENCFORGE, a compiled Go ransomware payload that encrypts model weights, vector indexes, checkpoints, and training data on the host, so the real loss can be the artifacts that make the model runnable.

Sysdig says the second attack reused CVE-2025-3248 in Langflow versions before 1.3.0 to reach the server again and deploy the new locker. The old campaign used throwaway scripts against downstream data stores; this one is built to sweep through common AI file types and hit the stores where ML systems keep their working state.

If model artifacts live beside the app, patching Langflow does not restore them. Without offline backups, encrypted weights and indexes can leave the AI service permanently unrecoverable even after the entry point is fixed.

4 sources · Jul 21

CVE-2025-3248

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. EPSS 100% (100th percentile).

CISA federal remediation date May 26 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-07-21

Every edition of this story: Langflow Intrusion Now Targets the Model Itself

More from today