Remote Code Execution Vulnerability in Flowise by FlowiseAI
CVE-2024-58351

9.3CRITICAL

Key Information:

Vendor

Flowise

Status
Vendor
CVE Published:
20 June 2026

What is CVE-2024-58351?

Flowise prior to version 2.1.4 is susceptible to a vulnerability where an attacker can inject malicious configurations into the Chainflow during runtime through the overrideConfig option. This setting is enabled by default for both frontend integration and backend Prediction API, lacking a proper allow-list for safe variables. Exploitation of this flaw can lead to severe consequences, including remote code execution, denial of service from server crashes, server-side request forgery, prompt injection, and the potential exposure of server variables and sensitive data. Attacks are confined to the affected server and do not persist across different users.

Affected Version(s)

Flowise 0 < 2.1.4

Flowise 2.1.4

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ryanhalliday
.