CVE-2025-3248 Langflow RCE via Base64 Python to python subprocess
Detects potential exploitation of CVE-2025-3248 in Langflow by identifying suspicious inbound network traffic targeting the /api/v1/validate/code endpoint, correlated with subsequent python child processes containing base64 decoding and execution primitives such as eval, exec, or subprocess.
Microsoft Sentinel (KQL)

