Code Execution Vulnerability in Flowise Product by FlowiseAI
CVE-2026-69251

9CRITICAL

Key Information:

Vendor

Flowiseai

Vendor
CVE Published:
4 August 2026

What is CVE-2026-69251?

CVE-2026-69251 is a code execution vulnerability identified in the Flowise product developed by FlowiseAI, which provides a drag-and-drop user interface to construct customized flows for large language models. This vulnerability affects versions prior to 3.1.3 and stems from an improper handling of TypeORM DataSource options in various record manager and memory nodes. Specifically, the flaw allows authenticated users to set arbitrary configurations via the additionalConfig input. By manipulating this input, a user can reference local JavaScript files that may lead to the execution of arbitrary code on the server. Organizations utilizing Flowise are at risk of significant security breaches, as this vulnerability can facilitate unauthorized code execution, leading to potential system compromise.

Potential impact of CVE-2026-69251

  1. Arbitrary Code Execution: The primary consequence of CVE-2026-69251 is the ability of an authenticated user to execute arbitrary code on the server. This capability can allow attackers to run malicious scripts, potentially leading to full system control and further exploitation of sensitive data.

  2. Data Breaches: With the ability to run arbitrary code, attackers could access, modify, or exfiltrate confidential data stored on the server. This can lead to significant data leaks, compliance violations, and reputational damage for affected organizations.

  3. System Compromise and Malware Infections: Exploiting this vulnerability can result in the installation of additional malicious software. Once attackers gain access, they can establish backdoors for re-entry, deploy ransomware, or orchestrate further attacks within the organization’s network.

Affected Version(s)

Flowise < 3.1.3

flowise-components < 3.1.3

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.