Detection of Multiple Vulnerabilities in Flowise Affecting Its Security

Published:
Illustrative image about Detection of Multiple Vulnerabilities in Flowise Affecting Its Security

On August 5, 2026, INCIBE-CERT issued an early warning about the existence of multiple vulnerabilities in Flowise affecting versions 3.1.2 and earlier, as well as flowise-components in the same versions or earlier as applicable. These vulnerabilities are classified as critical and could allow for remote code execution, reading sensitive information, credential theft, sandbox escape, privilege escalation, or complete compromise of the server hosting the application.

Overview of Vulnerabilities in Flowise

Flowise has identified and fixed a total of ten critical vulnerabilities. These affect different components and security mechanisms of the software. Among the flaws are vulnerabilities that allow remote code execution through the upload of arbitrary JavaScript files, escape from the vm2-based sandbox, insecure modification of security configurations in the NodeVM environment, and injection of Python code in the CSV Agent component.

Technical Details of Detected Vulnerabilities

Additional image about Detection of Multiple Vulnerabilities in Flowise Affecting Its Security
  • CVE-2026-69251: Sandbox escape vulnerability in the TypeORM/MySQL Record Manager that allows an authenticated user to upload arbitrary JavaScript files through insecure TypeORM options. This enables remote code execution and complete server compromise.
  • CVE-2026-69253: The vm2-based isolation can be bypassed by an authenticated user, allowing escape from the JavaScript sandbox and execution of arbitrary code on the server.
  • CVE-2026-69254: Allows an authenticated user to modify the security configuration of the NodeVM environment to enable restricted Node.js modules and execute arbitrary commands on the system with Flowise process privileges.
  • CVE-2026-69255: Python code injection through the csvFile parameter in the CSV Agent component, enabling remote execution via Pyodide.
  • CVE-2026-69256: Insufficient validation of Python code in CSVAgent that allows an authenticated user to execute arbitrary code using the pandas.read_pickle() function to deserialize maliciously manipulated objects.
  • CVE-2026-69259: Allows overwriting the SQLite database path, which, along with running the Docker image as root, facilitates remote code execution.
  • CVE-2026-70470: An attacker can bypass blacklists using Unicode homoglyph identifiers, allowing execution of operating system commands on the Flowise host.
  • CVE-2026-69264: In CSVAgent, the context of the Python string literal can be broken, allowing the import of built-in Node modules and execution of arbitrary I/O or operating system commands under the Flowise process.
  • CVE-2026-70477: Message injection in a chat flow that allows bypassing validators and isolation, enabling execution of arbitrary code in the context of the user running the server.
  • CVE-2026-70478: The update endpoint does not require authentication, which could allow an attacker to obtain an OAuth credential and request tokens to access the victim's connected services.

Affected Versions and Available Update

The vulnerabilities affect Flowise in versions 3.1.2 and earlier, as well as flowise-components in versions 3.1.2 and earlier as applicable. Flowise has fixed these issues in version 3.1.3. It is recommended to update to this version or a later one to incorporate the applied fixes.

Context of the Notice and Official Sources

The notice, identified as INCIBE-2026-532, has been published by INCIBE-CERT, the computer security incident response center in Spain. It details the nature of the vulnerabilities, their severity, and the affected versions. No data on active exploitation is included, nor are the conclusions extended to environments other than those affected.

The complete information can be found at the original source.

Reviewed by
Published: 06/08/2026. Content reviewed using experience, authority and trustworthiness criteria (E-E-A-T).
Responsible use of AI
This article may have used artificial intelligence tools to support structure, editing, translation or review. Editorial responsibility and final review remain with Toni Berraquero. View AI policy
Photo of Toni
Article author
Toni Berraquero

Toni Berraquero has trained since the age of 12 and has experience in retail, private security, ecommerce, digital marketing, marketplaces, automation and business tools.

View Toni’s profile

☕ If this genuinely helped…

You can support the project or share this article in one click. At least this block does something useful.