CVE-2026-52098

An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint

  • Published Sep 10, 2026
  • CVSS 9.8 critical
  • 1.1% chance of exploitation in the next 30 days (EPSS)

CVE-2026-52098 at the National Vulnerability Database