CVE-2026-69257 | FlowiseAI Flowise up to 3.1.2 HTTP Security httpSecurity.ts isDeniedIP incomplete blacklist

SecurityVulns

A vulnerability identified as critical has been detected in FlowiseAI Flowise up to 3.1.2. This affects the function isDeniedIP of the file httpSecurity.ts of the component HTTP Security Module. The manipulation leads to incomplete blacklist.

This vulnerability is uniquely identified as CVE-2026-69257. The attack is possible to be carried out remotely. No exploit exists.

You should upgrade the affected component.VulDB Recent EntriesRead More