Code Execution Vulnerability in Flowise Product by FlowiseAI
CVE-2026-69251

9CRITICAL

Key Information:

Vendor

Flowiseai

Vendor
CVE Published:
4 August 2026

What is CVE-2026-69251?

Flowise, a user-friendly interface for building customized large language model flows, contains a vulnerability that allows authenticated users to manipulate TypeORM DataSource configurations through the additionalConfig input. This flexibility leads to potential code execution on the server, as malicious users can upload JavaScript payloads and reference these files to gain unauthorized access. This vulnerability, fixed in version 3.1.3, underscores the importance of rigorous input validation and restrictions on configuration options.

Affected Version(s)

Flowise < 3.1.3

flowise-components < 3.1.3

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.