What is CVE-2026-69251?
The CVE-2026-69251 vulnerability in Flowise LLM flow builder allows arbitrary TypeORM DataSource options to be set via the "additionalConfig" input in record manager and agent memory nodes. This affects versions prior to 3.1.3. Immediate upgrade to the latest version is recommended.
Azərbaycanca: Flowise LLM axın qurucusunda müəyyən edilmiş CVE-2026-69251 boşluğu, record manager və agent memory qovşaqlarının TypeORM DataSource seçimlərini "additionalConfig" girişi vasitəsilə ixtiyari təyin etməyə imkan verir. Bu zəiflik 3.1.3 versiyasından əvvəlki versiyalara təsir edir. Dərhal ən son versiyaya yeniləmə tövsiyə olunur.
FAQ2
Which nodes in Flowise are affected by CVE-2026-69251?
The CVE-2026-69251 vulnerability affects the record manager and agent memory nodes, allowing arbitrary TypeORM DataSource options to be set via the "additionalConfig" input.
Which version is recommended to upgrade to in order to mitigate CVE-2026-69251?
Since this vulnerability affects versions prior to 3.1.3, an immediate upgrade to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.