CVE-2026-69254 | FlowiseAI Flowise up to 3.1.2 JavaScript Code Execution utils.ts executeJavaScriptCode nodeVMOptions command injection

SecurityVulns

A vulnerability labeled as very critical has been found in FlowiseAI Flowise up to 3.1.2. This vulnerability affects the function executeJavaScriptCode of the file packages/components/src/utils.ts of the component JavaScript Code Execution. Such manipulation of the argument nodeVMOptions leads to command injection.

This vulnerability is referenced as CVE-2026-69254. It is possible to launch the attack remotely. No exploit is available.

The affected component should be upgraded.VulDB Recent EntriesRead More