Flowise < 3.1.3 - Remote Code Execution
CVE-2026-69251
Verified
Description
Flowise prior to 3.1.3 contains a remote code execution vulnerability caused by allowing authenticated users to set arbitrary TypeORM DataSource options including entities that load local JavaScript files, letting authenticated users execute arbitrary code on the server, exploit requires user authentication.
Severity
Critical
CVSS Score
9
Exploit Probability
3%
Affected Product
flowise
Published Date
August 4, 2026
Template Author
1dayexploit
CVE-2026-69251.yaml
9.0Score
CVSS Metrics
CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVE ID:
cve-2026-69251
CWE ID:
cwe-94
Remediation Steps
Update to version 3.1.3 or later.