Improper access control in Flowise - CVE-2026-41268
Published: May 4, 2026
Flowise
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper access control in the replaceInputsWithConfig function when handling overrideConfig parameters containing the FILE-STORAGE:: keyword. A remote attacker can send a specially crafted HTTP request to execute arbitrary code.
Exploitation requires a public chatflow with API Override enabled and an MCP tool node present.