Arbitrary Command Execution Vulnerability in Flowise by FlowiseAI
CVE-2026-69254

9.4CRITICAL

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-69254?

An issue in Flowise prior to version 3.1.3 allows an authenticated attacker to exploit the executeJavaScriptCode() function. By manipulating nodeVMOptions, an attacker could potentially use custom functions to bypass default security settings. This flaw enabled the execution of arbitrary system commands as root, compromising the security of the Flowise server. It is crucial for users to update to version 3.1.3 or later to mitigate this vulnerability.

Affected Version(s)

Flowise < 3.1.3

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.