CVE-2026-52098
An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint
- Published Sep 10, 2026
- CVSS 9.8 critical
- 1.1% chance of exploitation in the next 30 days (EPSS)
An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint