What is CVE-2026-69258?
CVE-2026-69258 is a critical vulnerability in Flowise where an unauthenticated `/api/v1/prediction/:id` endpoint unconditionally spreads an attacker-controlled `overrideConfig` object into internal server configurations. This could allow unauthorized manipulation of the LLM flow. Users must upgrade to version 3.1.3 immediately.
Azərbaycanca: CVE-2026-69258 Flowise-in autentifikasiya olunmamış `/api/v1/prediction/:id` endpoint-ində təhlükəli zəiflikdir. Bu, xarici `overrideConfig` vasitəsilə server konfiqurasiyasına müdaxilə etməyə imkan verir. İstifadəçilər dərhal 3.1.3 versiyasına yeniləməlidir.
Related CVEs
link basis: shared vendor: Flowise
FAQ2
Which Flowise endpoint is affected by CVE-2026-69258 and how can it be exploited?
The vulnerability affects the unauthenticated `/api/v1/prediction/:id` endpoint. It allows interference with server configuration via an external `overrideConfig` object.
What action is required to mitigate CVE-2026-69258?
Users must upgrade to Flowise version 3.1.3 immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.