Code Execution Vulnerability in Flowise Product by FlowiseAI
CVE-2026-69251
What is CVE-2026-69251?
CVE-2026-69251 is a code execution vulnerability identified in the Flowise product developed by FlowiseAI, which provides a drag-and-drop user interface to construct customized flows for large language models. This vulnerability affects versions prior to 3.1.3 and stems from an improper handling of TypeORM DataSource options in various record manager and memory nodes. Specifically, the flaw allows authenticated users to set arbitrary configurations via the additionalConfig input. By manipulating this input, a user can reference local JavaScript files that may lead to the execution of arbitrary code on the server. Organizations utilizing Flowise are at risk of significant security breaches, as this vulnerability can facilitate unauthorized code execution, leading to potential system compromise.
Potential impact of CVE-2026-69251
-
Arbitrary Code Execution: The primary consequence of CVE-2026-69251 is the ability of an authenticated user to execute arbitrary code on the server. This capability can allow attackers to run malicious scripts, potentially leading to full system control and further exploitation of sensitive data.
-
Data Breaches: With the ability to run arbitrary code, attackers could access, modify, or exfiltrate confidential data stored on the server. This can lead to significant data leaks, compliance violations, and reputational damage for affected organizations.
-
System Compromise and Malware Infections: Exploiting this vulnerability can result in the installation of additional malicious software. Once attackers gain access, they can establish backdoors for re-entry, deploy ransomware, or orchestrate further attacks within the organization’s network.
Affected Version(s)
Flowise < 3.1.3
flowise-components < 3.1.3
