Impact
Flowise version 3.1.2 contains a code‑injection flaw that allows an attacker who can reach the /api/v1/prediction/<flowId> endpoint to inject and execute arbitrary code on the server. This vulnerability, classified as CWE‑94, gives an attacker full control over the underlying system, compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerable product is Flowise 3.1.2. No other releases are reported as affected. The CDA lists the product as Flowise, and the affected version is specifically 3.1.2.
Risk and Exploitability
The CVSS score of 9.8 places this flaw in the critical range. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker sending a crafted request to the /api/v1/prediction endpoint, which bypasses validation and triggers execution. Because the flaw resides in server code, an attacker does not need any privileged client permissions; remote code execution is achievable over the network.
OpenCVE Enrichment