Code Execution Vulnerability in Flowise Product by FlowiseAI
CVE-2026-69251
9CRITICAL
What is CVE-2026-69251?
Flowise, a user-friendly interface for building customized large language model flows, contains a vulnerability that allows authenticated users to manipulate TypeORM DataSource configurations through the additionalConfig input. This flexibility leads to potential code execution on the server, as malicious users can upload JavaScript payloads and reference these files to gain unauthorized access. This vulnerability, fixed in version 3.1.3, underscores the importance of rigorous input validation and restrictions on configuration options.
Affected Version(s)
Flowise < 3.1.3
flowise-components < 3.1.3
