Improper access control in Flowise - CVE-2024-58351
Published: November 21, 2024 / Updated: September 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper access control in the overrideConfig option when processing user-supplied configuration through the Prediction API or web embed integration. A remote attacker can supply crafted overrideConfig values to execute arbitrary code.
The code execution occurs inside a sandbox.