GHSA-qj5g-x3q9-pvxjCriticalCVSS 9.8
An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1...
🔗 CVE IDs covered (1)
📋 Description
An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/ endpoint
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-52098
- https://github.com/FlowiseAI/Flowise
- https://github.com/FlowiseAI/Flowise/blob/main/packages/server/src/utils/constants.ts
- https://github.com/FlowiseAI/Flowise/blob/main/packages/server/src/utils/validateKey.ts
- https://github.com/advisories/GHSA-qj5g-x3q9-pvxj