Unauthenticated Remote Command Execution Vulnerability in Flowise by FlowiseAI
CVE-2026-41268
What is CVE-2026-41268?
Flowise, created for building customized large language model flows, was susceptible to an unauthenticated remote command execution vulnerability prior to version 3.1.0. This flaw allowed attackers to execute arbitrary system commands with root privileges within the containerized environment by leveraging a parameter override bypass technique through the FILE-STORAGE:: keyword, along with NODE_OPTIONS environment variable injection. Successful exploitation required only a single HTTP request, with no authentication or knowledge of the instance necessary. This vulnerability was addressed in the 3.1.0 release, underscoring the importance of updating immediately.
Affected Version(s)
Flowise < 3.1.0
References
EPSS Score
13% chance of being exploited in the next 30 days.
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
