CVE-2026-69253 | FlowiseAI Flowise up to 3.1.2 AgentAsTool/ChatflowTool/ExecuteFlow isValidURL baseURL code injection
A vulnerability identified as critical has been detected in FlowiseAI Flowise up to 3.1.2. This affects the function isValidURL of the component AgentAsTool/ChatflowTool/ExecuteFlow. This manipulation of the argument baseURL causes code injection.
The identification of this vulnerability is CVE-2026-69253. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More