Flowise v3.1.2 and earlier are vulnerable to unauthenticated remote code execution because the CVE-2025-8943 patch relies on an incomplete environment variable blocklist, allowing attackers to inject configuration variables that force arbitrary package installation.
Flowise +6
rce
injection
cve-2026-69263
python-injection
authentication-bypass
oauth
cve-2026-70478
web-vulnerability
+7
6r
11t
8c
2i
updated