Flowise · Flowise · CVE-2024-58351
**Name of the Vulnerable Software and Affected Versions**
Flowise versions prior to 2.1.4
**Description**
Configuration can be injected into the Chainflow during execution through the `overrideConfig` option, which is available in the frontend web integration and the backend Prediction API. This feature is enabled by default without an allow-list of permitted variables and utilizes vm2 for sandboxing. An attacker can exploit this to achieve remote code execution and sandbox escape, cause a denial of service by crashing the server, perform server-side request forgery, execute prompt injection, and exfiltrate server variables and data. These issues are self-targeted, require no privileges or user interaction, and do not persist to other users.
**Recommendations**
Update to version 2.1.4.