CVE-2026-69264 – Flowise

CVSS 9.4 CRITICAL Zero Day – Immediate Deployment

“Multiple paths to server-side code execution make this a high-impact Flowise update.”

Flowise 3.1.3 fixes a broad set of vulnerabilities affecting agent nodes, record managers, sandbox controls, TypeORM configuration, Pyodide execution, and custom JavaScript handling. CVE-2026-69251, CVE-2026-73601, CVE-2026-69253, CVE-2026-73602, CVE-2026-73485, CVE-2026-73486, and CVE-2026-73487 each have a CVSS score of 9.0, Critical severity. CVE-2026-69256, CVE-2026-69259, CVE-2026-69264, and CVE-2026-69254 each have a CVSS score of 9.4, Critical severity. CVE-2026-69255 has a CVSS score of 9.2, Critical severity. CVE-2026-70477 and CVE-2026-70470 each have a CVSS score of 9.5, Critical severity. CVE-2026-73484 has a CVSS score of 8.6, High severity.

Several flaws provide remote code execution paths through crafted configuration, prompt injection, unsafe Python execution, sandbox escapes, and validator bypasses. Public proof-of-concept exploitation is confirmed for multiple issues in this group. Flowise 3.1.3 contains the fixes.

Key Details

CWE Classification
CWE-94
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.