GHSA-5w6g-rc45-wvv9Critical· 9.8▾ MidnightDuplicate Advisory: Flowise OverrideConfig security vulnerability
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-5cph-wvm9-45gj. This link is maintained to preserve external references.
Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the frontend web integration and the backend Prediction API. Because this feature is enabled by default with no allow-list of permitted variables and relies on vm2 for sandboxing, an attacker can abuse it to achieve remote code execution and sandbox escape, denial of service by crashing the server, server-side request forgery, prompt injection, and server variable and data exfiltration. These issues are self-targeted and do not persist to other users.
flowise < 2.1.4Upgrade to a patched release:
flowise 2.1.4Connected by shared product, vendor, weakness, or advisory.
CVE-2024-58351HighFlowise OverrideConfig security vulnerability
CVE-2026-70477Critical· 9.8Flowise is a drag & drop user interface to build a customized large language model flow
CVE-2026-69264Critical· 9.8Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide
CVE-2026-69255High· 8.8Flowise is a drag & drop user interface to build a customized large language model flow
CVE-2026-69256High· 8.8Flowise is a drag & drop user interface to build a customized large language model flow
CVE-2026-69259High· 8.8Flowise is a drag & drop user interface to build a customized large language model flow