CVE-2026-52098
A critical flaw in Flowise 3.1.2 lets attackers run any code on the server by hitting a specific API endpoint. The vulnerability can be triggered over the network without authentication or user interaction. It poses a severe risk to any system running that version.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Flowise 3.1.2 (the web‑based data flow platform).
Real-world impact
An attacker who can reach the /api/v1/prediction/<flowId> endpoint can execute arbitrary code on the host, potentially taking full control of the server, stealing data, or using it for further attacks.
Why this severity
The CVSS score of 9.8 reflects that the flaw is exploitable from anywhere on the network, requires no user interaction or special privileges, and gives the attacker complete confidentiality, integrity, and availability compromise.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources