Summary
CVE-2026-69258 is an unauthenticated property injection vulnerability in Flowise, the open-source generative AI agent building platform. The POST /api/v1/prediction/:id prediction endpoint spreads an attacker-supplied overrideConfig object into internal execution objects without authorization checks, allowing manipulation of a public chatflow’s execution context. It affects Flowise versions up to and including 3.1.2 and is rated High severity (CVSS 8.8).
Technical details
- Root cause: The prediction endpoint takes the
incomingInput.overrideConfigobject and spreads it directly intoflowConfigandflowDatawith no gating and without verifyingapiOverrideStatus(buildChatflow.ts and index.ts). - Trigger conditions: A public (unauthenticated) chatflow receiving a crafted POST request whose
overrideConfigcontains injected properties. - Attack vector: Network, no authentication, low complexity.
- Impact: Attackers can inject arbitrary properties into the flow execution context — overriding values such as
chatId,sessionId, andchatHistory(enabling session manipulation and injected chat history), and defining properties that become accessible to node templates via$flow.*variable references. - Classification: CWE-639 (Authorization Bypass Through User-Controlled Key) and CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes).
Affected software
- Flowise (npm
flowise) versions ≤ 3.1.2.
Severity
- CVSS v4.0 base score: 8.8 (High)
- Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Upgrade to Flowise 3.1.3, which replaces the ungated spread with explicit property handling.
- If no patch: Restrict network access to the prediction API, avoid exposing public/unauthenticated chatflows to the internet, and enforce authentication on prediction endpoints. Where feasible, restrict or allowlist permitted
overrideConfigproperties and block overrides of sensitive fields such aschatId,sessionId,chatHistory, andapiMessageId.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Flowise - Build AI Agents, Visually,Flowise - Low-code LLM apps builder - A meta tag’s content:
FlowiseAI,Open source generative AI development platform for building AI agents - Raw response body:
data-rewardful="9a3a26",og:site_name…flowiseai.com

