Improper access control in Flowise - CVE-2026-69259
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in the SQLite Record Manager node when processing user-supplied additional configuration. A remote user can override the database path to write a crafted SQLite database to an arbitrary file and trigger command execution to execute arbitrary code.
Exploitation requires an authenticated user and affects instances using the published Docker image where the process runs as root. A separate Puppeteer launch is used to read the malicious file from /etc/chromium/*.conf.