Protection Mechanism Failure in Flowise - #VU129626

 

Protection Mechanism Failure in Flowise - #VU129626

Published: November 21, 2024 / Updated: May 4, 2026


Vulnerability identifier: #VU129626
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to improper sandboxing in the overrideConfig option when processing user-supplied configuration through the Prediction API or web embed integration. A remote attacker can supply crafted overrideConfig values to escape the sandbox.

This issue is described as reachable through both the API and the web embed integration.


Affected software

Flowise

Remediation

Install security update from vendor's website.

Flowise - update to 2.1.4

External References

Related Security Bulletins