Improper Neutralization of Special Elements in Data Query Logic in Flowise - #VU146554

 

Improper Neutralization of Special Elements in Data Query Logic in Flowise - #VU146554

Published: September 1, 2026


Vulnerability identifier: #VU146554
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-943
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper neutralization of special elements used in a NoSQL command in MongoDBMemory node when handling Prediction API requests with a crafted overrideConfig.sessionId value. A remote attacker can send a specially crafted request containing a MongoDB operator object to disclose sensitive information.

The issue can expose chat history records from arbitrary other users in a shared MongoDB collection, including sensitive data disclosed to the AI agent. Public chatflows can be reached without authentication through the prediction endpoint.


Affected software

Flowise

Remediation

Install security update from vendor's website.

Flowise - update to 3.1.4

External References

Related Security Bulletins