CVE-2026-69258Disclosure(flowiseai / flowise)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch flowiseai flowise systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in packages/server/src/utils/buildChatflow.ts and packages/server/src/utils/index.ts without checking apiOverrideStatus. This allowed unauthenticated attackers to inject arbitrary properties into the flow execution context of any public chatflow, overwrite values such as chatId, sessionId, and chatHistory, and control values resolved through $flow.* template variables consumed by flow nodes. This issue is fixed in version 3.1.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639CWE-915

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-08-30)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-07: 1Mentions · 2026-08-30: 2Patch / Workaround · 2026-08-07: 1Technical Details · 2026-08-30: 108-0708-30
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-071
Disclosure1
2026-08-302
Disclosure1General1
Full discourse3 posts
  • Bug bounty wizard@bugbountywizard
    Disclosure

    CVE-2026-69258: Flowise Patched OverrideConfig — I Found the Two Places the Patch Never Reached — by Aviral https://medium.com/@aviral23/cve-2026-69258-flowise-patched-overrideconfig-i-found-the-two-places-the-patch-never-reached-cb907387cbbe Join us on Telegram: https://t.me/bugbountywizard #bugbounty #bugbountytips #bugbountytip

    Post summary

    The Medium article highlights that the patch for CVE-2026-69258 in Flowise did not propagate to two critical areas, drawing attention to a potential oversight in the patch deployment.

    01093602
    2.2K followersView on X
  • HackerNoon | Learn Any Technology@hackernoon
    Disclosure

    CVE-2026-69258: two ungated spread operators let an unauthenticated caller write into the flow execution context of any public Flowise chatflow. #flowisevulnerability #aiagentsecurity...Show more https://t.co/y8t9ShPScj

    Post summary

    The tweet announces CVE‑2026‑69258, detailing how ungated spread operators allow an unauthenticated user to write into a Flowise chatflow's execution context. No PoC, exploit, patch, or active exploitation information is provided.

    110001.9K
    94.8K followersView on X
  • HackerNoon | Learn Any Technology@hackernoon
    General

    Read the full story👇 https://hackernoon.com/the-spread-operator-is-an-allowlist-with-nothing-in-it-cve-2026-69258-in-flowise

    Post summary

    The text simply links to an article discussing CVE-2026-69258 in Flowise, providing no additional context or technical information.

    00000185
    94.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more