PT-2026-51142 · Flowise · Flowise

·

CVE-2024-58351

·

Published

2024-11-21

·

Updated

2026-06-22

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 2.1.4
Description Configuration can be injected into the Chainflow during execution through the overrideConfig option, which is available in the frontend web integration and the backend Prediction API. This feature is enabled by default without an allow-list of permitted variables and utilizes vm2 for sandboxing. An attacker can exploit this to achieve remote code execution and sandbox escape, cause a denial of service by crashing the server, perform server-side request forgery, execute prompt injection, and exfiltrate server variables and data. These issues are self-targeted, require no privileges or user interaction, and do not persist to other users.
Recommendations Update to version 2.1.4.

Exploit

Fix

RCE

DoS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-58351
GHSA-5CPH-WVM9-45GJ

Affected Products

Flowise