CVE-2026-52098
9.8FlowiseAI · Flowise
Flowise 3.1.2 and earlier allow unauthenticated remote attackers to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint.
Executive summary
A critical remote code execution vulnerability in Flowise allows unauthenticated attackers to gain full system control.
Vulnerability
This vulnerability involves an improper validation of input within the prediction API endpoint, which permits an unauthenticated attacker to inject and execute arbitrary code on the host server. The flaw stems from insufficient security controls in the prediction processing logic.
Business impact
The CVSS score of 9.8 reflects the extreme severity of this flaw, as it allows for full system compromise without any user interaction or authentication. Successful exploitation grants attackers the ability to steal sensitive AI models, exfiltrate data, or deploy persistent backdoors, posing a severe risk to organizational confidentiality and integrity. Given that this is part of a batch of critical vulnerabilities, including one with confirmed active exploitation, the urgency for remediation is absolute.
Remediation
Immediate Action: Upgrade all instances of Flowise to version 3.1.3 or later immediately to patch the vulnerable prediction endpoint.
Proactive Monitoring: Review application access logs for suspicious requests directed at the /api/v1/prediction/ path, specifically looking for unexpected payloads or anomalous execution patterns.
Compensating Controls: Deploy a Web Application Firewall (WAF) with custom rules to inspect and block malicious input patterns targeted at the prediction API until the patch is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a critical threat to the security of your AI infrastructure. Organizations must prioritize upgrading to version 3.1.3 immediately, as the potential for total system takeover is significant. Given the context of active exploitation within the Flowise software suite, failure to patch these systems leaves your environment at high risk of compromise.
More FlowiseAI CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Analyst report updated
- Published in the daily brief critical section