An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint
References
Configurations
History
No history.
Information
Published : 2026-09-10 17:17
Updated : 2026-09-15 19:09
NVD link : CVE-2026-52098
Mitre link : CVE-2026-52098
CVE.ORG link : CVE-2026-52098
JSON object : View
Products Affected
flowiseai
- flowise
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
