Vulnerabilities · 55 days ago

Langflow Intrusion Now Targets the Model Itself

Once an attacker has Langflow, cleaning the app does not protect the AI system anymore. JADEPUFFER has shifted from improvised destruction to ENCFORGE, a compiled Go ransomware payload that encrypts model weights, vector indexes, checkpoints, and training data on the host, so the real loss can be the artifacts that make the model runnable.

Sysdig says the second attack reused CVE-2025-3248 in Langflow versions before 1.3.0 to reach the server again and deploy the new locker. The old campaign used throwaway scripts against downstream data stores; this one is built to sweep through common AI file types and hit the stores where ML systems keep their working state.

If model artifacts live beside the app, patching Langflow does not restore them. Without offline backups, encrypted weights and indexes can leave the AI service permanently unrecoverable even after the entry point is fixed.

CVE-2025-3248

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. EPSS 100% (100th percentile).

CISA federal remediation date May 26 · date passed

Timeline

Sources

4 sources covering this story

Entities

Part of the PlainSec briefing for 2026-07-22

Editions

Related stories