A high-severity vulnerability in Flowise, tracked as CVE-2026-69258, allows unauthenticated attackers to tamper with the execution context of public chatflows through the POST /api/v1/prediction/:id endpoint. In affected versions before 3.1.3, the application accepted an overrideConfig object and merged it into internal flowConfig and flowData structures without enforcing apiOverrideStatus, enabling attackers to overwrite values such as sessionId, chatId, and chatHistory and bypass session isolation.
The flaw can let attackers access, pollute, or hijack other users’ conversations and inject arbitrary properties into the $flow.* namespace used by flow nodes, including variables that may influence SQL queries, webhooks, and API integrations. The issue is rated CVSS 8.8 and mapped to CWE-639 and CWE-915; while it does not directly provide operating-system-level remote code execution, it can break logical security boundaries and corrupt routing, prompt history, and downstream workflow behavior. Flowise patched the issue in version 3.1.3, and users are advised to upgrade.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE entry states that security-advisories@github.com received the new CVE report for CVE-2026-69258 on August 4, 2026.
The Medium post states the issue was reported to FlowiseAI through a GitHub Security Advisory in March 2026. Flowise acknowledged the report within three days and confirmed the severity as High.
Flowise addressed the unauthenticated overrideConfig property injection and authorization bypass issue in version 3.1.3. The fix removed the vulnerable spread of overrideConfig into internal flow execution objects, with references pointing to commit 23b997ee5ef9e269b628bad0f56f1ecb86bd2fca and related remediation materials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
medium.com
Open sourcecvefeed.io
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.