CVE-2024-58351Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-06-21); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-06-20: 2Mentions · 2026-06-21: 3Mentions · 2026-06-22: 1Patch / Workaround · 2026-06-20: 1Patch / Workaround · 2026-06-21: 1Technical Details · 2026-06-20: 2Technical Details · 2026-06-21: 3Technical Details · 2026-06-22: 106-2006-2106-22
Signal classification3 categories
Disclosure
466.7%
Patch
116.7%
General
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-202
Disclosure1Patch1
2026-06-213
Disclosure3
2026-06-221
General1
Full discourse6 posts
  • ADK Cyber@ADKCyber
    Disclosure

    CVE-2024-58351 (CVSS 9.8): Flowise <2.1.4 allows config injection via overrideConfig. Update immediately if using this tool. https://nvd.nist.gov/vuln/detail/CVE-2024-58351 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/6VfYOi0taZ

    Post summary

    The post announces the high‑severity CVE‑2024‑58351, a config injection flaw in Flowise <2.1.4, and urges users to update.

    0001066
    93 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Flowise overrideConfig Code Injection / vm2 Sandbox Escape (CVE-2024-58351) Flowise lets configuration be injected into the Chainflow at execution time through the overrideConfig option, exposed in both the frontend web integration and the backend Prediction API. The feature is enabled by default with no allow-list of permitted variables and relies on vm2 for sandboxing. An attacker can abuse this to achieve remote code execution and vm2 sandbox escape, along with denial of service by crashing the server, server-side request forgery, prompt injection, and exfiltration of server variables and data. The issues are self-targeted and do not persist to other users. Exploitation requires no privileges and no user interaction. 👉Upgrade to Flowise 2.1.4.

    Post summary

    The tweet discloses CVE-2024-58351, describing a remote code execution flaw via Flowise's overrideConfig, and advises users to update to Flowise 2.1.4 to mitigate the vulnerability.

    1000069
    223 followersView on X
  • NerdieNews@NewsNerdie
    General

    🔴 Attackers can exploit CVE-2024-58351 in Flowise (&lt;v2.1.4) to execute remote code via the overrideConfig parameter. This could lead to full system compromise. #NerdieNews #CyberSecurity #ThreatIntel https://t.co/P1dZ468rWi

    Post summary

    The tweet highlights a remote code execution vulnerability in Flowise (v<2.1.4) via the overrideConfig parameter, but offers no PoC, active exploitation evidence, patch, or debunking claim.

    0000039
    68 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2024-58351 Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the frontend web integra… https://www.cve.org/CVERecord?id=CVE-2024-58351 ----- Traducción: CVE-2024-58351 Flo… http://infoflow.cloud`

    Post summary

    CVE‑2024‑58351 is a configuration injection flaw in Flowise less than 2.1.4, enabling overrideConfig to inject into Chainflow during execution. The post supplies the vulnerability description but lacks PoC, exploit code, patch details, or exploitation evidence.

    0000035
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2024-58351 Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the frontend web integra… https://www.cve.org/CVERecord?id=CVE-2024-58351

    Post summary

    The post announces CVE-2024-58351, detailing that Flowise before 2.1.4 allows configuration injection via overrideConfig, without offering PoC, exploits, patches, or evidence of active exploitation.

    00000350
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2024-58351 Configuration Injection Remote Code Execution in Flowise Before 2.1.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2024-58351

    Post summary

    The excerpt provides a brief disclosure of CVE‑2024‑58351, detailing a configuration injection remote code execution flaw in Flowise versions prior to 2.1.4, but offers no concrete PoC, exploit code, mitigation, or active exploitation data.

    0000043
    4.1K followersView on X

Explore more