CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2026-73487: flowise <= 3.1.2; +1 more affected products

CVE-2026-73487 affects flowise. EPSS 0.00769 (percentile 0.5412), scored 2026-10-06. Affected range: <= 3.1.2. Fixed version: 3.1.3. Affected range: <= 3.1.2. Fixed version: 3.1.3.

Affected technology

flowise · <= 3.1.2
Vendor not specified by the source

flowise-components · <= 3.1.2
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

An attacker can exfiltrate all loaded data to an external server, perform SSRF against internal services, and potentially achieve further code execution -- all through prompt injection via the unauthenticated prediction API.

Published

Product
flowise
CCR priority
0.2 /100 (P5)
EPSS
0.00769 · percentile 0.5412 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-73487.html