Arbitrary Command Execution Vulnerability in Flowise by FlowiseAI
CVE-2026-69254
9.4CRITICAL
What is CVE-2026-69254?
An issue in Flowise prior to version 3.1.3 allows an authenticated attacker to exploit the executeJavaScriptCode() function. By manipulating nodeVMOptions, an attacker could potentially use custom functions to bypass default security settings. This flaw enabled the execution of arbitrary system commands as root, compromising the security of the Flowise server. It is crucial for users to update to version 3.1.3 or later to mitigate this vulnerability.
Affected Version(s)
Flowise < 3.1.3
