What is CVE-2026-69254?
CVE-2026-69254 is a vulnerability in Flowise, a UI for building custom LLM flows. The executeJavaScriptCode() function merges user-supplied nodeVMOptions over default NodeVM security settings, allowing an authenticated attacker to potentially bypass restrictions and execute arbitrary code. Users should upgrade to version 3.1.3 or later.
Azərbaycanca: CVE-2026-69254 Flowise platformasında aşkarlanmış zəiflikdir. executeJavaScriptCode() funksiyası təhlükəsizlik parametrlərini istifadəçi tərəfindən təqdim olunan nodeVMOptions ilə əvəz etməyə imkan verir ki, bu da autentifikasiya olunmuş hücumçuya xüsusi kod icra etməyə şərait yaradır. 3.1.3 versiyasına qədər yeniləmə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: Flowise
FAQ2
Which function in the Flowise platform is affected by CVE-2026-69254?
The executeJavaScriptCode() function merges user-supplied nodeVMOptions over default NodeVM security settings.
To which version should users upgrade to mitigate CVE-2026-69254?
Users should upgrade to version 3.1.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.