PT-2026-34734 · Flowise · Flowise

Published

2026-04-16

·

Updated

2026-04-23

·

CVE-2026-41269

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.0
Description The Chatflow configuration file upload settings can be modified to allow the 'application/javascript' MIME type. This allows the upload of .js files, bypassing frontend restrictions. An attacker can use this to persistently store malicious Node.js web shells on the server, which may lead to Remote Code Execution (RCE), a process where an attacker can execute arbitrary commands on the target machine.
Recommendations Update to version 3.1.0.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41269
GHSA-RH7V-6W34-W2RR

Affected Products

Flowise