CVE-2024-58351High▾ TwilightFlowise OverrideConfig security vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.9%
Flowise allows developers to inject configuration into the Chainflow during execution through the overrideConfig option. This is supported in both the frontend web integration and the backend Prediction API.
This has a range of fundamental issues that are a major security vulnerability. While this feature is intentional, it should have strong protections added and be disabled by default.
These issues include:
These issues are self-targeted and do not persist to other users but do leave the server and business exposed. All issues are shown with the API but also work with the web embed.
overrideConfig should be disabled by defaultoverrideConfig should have an explicit allow list of variables that are allowed to be modified. This way the user opts-in to where modifications can be made.vm2 and any forks of it should be removed as in the authors own words, "fixing the vulnerability seems impossible". The recommended replacement is https://www.npmjs.com/package/isolated-vmflowise < 2.1.4Upgrade to a patched release:
flowise 2.1.4Connected by shared product, vendor, weakness, or advisory.
GHSA-5w6g-rc45-wvv9Critical· 9.8Duplicate Advisory: Flowise OverrideConfig security vulnerability
CVE-2026-70475Medium· 6.5Flowise is a drag & drop user interface to build a customized large language model flow
GHSA-8gj2-2cvc-6xx7MediumFlowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
CVE-2026-70476High· 8.2Flowise is a drag & drop user interface to build a customized large language model flow
CVE-2026-70477Critical· 9.8Flowise is a drag & drop user interface to build a customized large language model flow
CVE-2026-70478Critical· 10.0Flowise is a drag & drop user interface to build a customized large language model flow