PT-2026-51142 · Flowise · Flowise
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Flowise versions prior to 2.1.4
Description
Configuration can be injected into the Chainflow during execution through the
overrideConfig option, which is available in the frontend web integration and the backend Prediction API. This feature is enabled by default without an allow-list of permitted variables and utilizes vm2 for sandboxing. An attacker can exploit this to achieve remote code execution and sandbox escape, cause a denial of service by crashing the server, perform server-side request forgery, execute prompt injection, and exfiltrate server variables and data. These issues are self-targeted, require no privileges or user interaction, and do not persist to other users.Recommendations
Update to version 2.1.4.
Exploit
Fix
RCE
DoS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flowise