What is CVE-2026-69253?
This vulnerability affects the 'AgentAsTool', 'ChatflowTool', and 'ExecuteFlow' custom tool components in Flowise, a drag-and-drop LLM flow builder. Before version 3.1.3, user-controlled code was executed in an in-process 'vm2' sandbox, posing potential code execution risks. Users should immediately upgrade to the latest version.
Azərbaycanca: Bu boşluq Flowise LLM axın qurucusunda 'AgentAsTool', 'ChatflowTool' və 'ExecuteFlow' xüsusi alət komponentlərini əhatə edir. 3.1.3 versiyasından əvvəl, istifadəçi tərəfindən idarə olunan kod 'vm2' sandbox-da işlədilir ki, bu da potensial kod icrası riskləri yaradır. İstifadəçilər dərhal ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which components of Flowise are affected by CVE-2026-69253?
This vulnerability affects the 'AgentAsTool', 'ChatflowTool', and 'ExecuteFlow' custom tool components.
What is the primary recommended mitigation for CVE-2026-69253?
Users should immediately upgrade to the latest version (3.1.3 or above).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.