CVE-2026-69258
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in packages/server/src/utils/buildChatflow.ts and packages/server/src/utils/index.ts without checking apiOverrideStatus. This allowed unauthenticated attackers to inject arbitrary properties into the flow execution context of any public chatflow, overwrite values such as chatId, sessionId, and chatHistory, and control values resolved through $flow.* template variables consumed by flow nodes. This issue is fixed in version 3.1.3.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.38%
- CWE
- CWE-639, CWE-915
- Published
- 2026-08-04
- Last modified
- 2026-08-05
Affected products
- FlowiseAI Flowise
Weakness type
Related vulnerabilities
- CVE-2026-84062 — BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through...
- CVE-2026-87997 — Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
- CVE-2026-87994 — Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
- CVE-2026-47156 — MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator
- CVE-2026-67403 — Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API....
- CVE-2026-86763 — snipe-it 7.0.12 through 8.6.3 Authorization Bypass via Importer
- CVE-2026-86761 — snipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpoints
- CVE-2026-86743 — Snipe-IT before 8.7.0 Authorization Bypass via Asset Acceptance Report