Skip to content

MCPA-2026-0052

criticalrce-vectors

Flowise RCE via TypeORM DataSource configuration (CVE-2026-69251)

Flowise 3.1.2 and earlier allow database node configuration to be abused through TypeORM DataSource options to execute arbitrary code on the host (reported by elttam). Fixed in 3.1.3.

Affected packages

EcosystemPackageAffected versions
npmflowise
>= 0, < 3.1.3
npmflowise-components
>= 0, < 3.1.3

Identifiers

CVE-2026-69251GHSA-g32j-mmxr-gfq5CWE-94

References

Timeline

  • Published: 2026-08-04

← All advisories