Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ryanhalliday

#27077of 56,327
9.8Total CVSS
Vulnerabilities · 1
PT-2026-51142
9.8
2024-11-21
Flowise · Flowise · CVE-2024-58351
**Name of the Vulnerable Software and Affected Versions** Flowise versions prior to 2.1.4 **Description** Configuration can be injected into the Chainflow during execution through the `overrideConfig` option, which is available in the frontend web integration and the backend Prediction API. This feature is enabled by default without an allow-list of permitted variables and utilizes vm2 for sandboxing. An attacker can exploit this to achieve remote code execution and sandbox escape, cause a denial of service by crashing the server, perform server-side request forgery, execute prompt injection, and exfiltrate server variables and data. These issues are self-targeted, require no privileges or user interaction, and do not persist to other users. **Recommendations** Update to version 2.1.4.