Get real-time updates on Telegram
P5Verified
CVE-2026-73487: flowise <= 3.1.2; +1 more affected products
CVE-2026-73487 affects flowise. EPSS 0.00769 (percentile 0.5412), scored 2026-10-06. Affected range: <= 3.1.2. Fixed version: 3.1.3. Affected range: <= 3.1.2. Fixed version: 3.1.3.
Affected technology
flowise · <= 3.1.2
Vendor not specified by the source
flowise-components · <= 3.1.2
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
An attacker can exfiltrate all loaded data to an external server, perform SSRF against internal services, and potentially achieve further code execution -- all through prompt injection via the unauthenticated prediction API.
- Product
- flowise
- CCR priority
- 0.2 /100 (P5)
- EPSS
- 0.00769 · percentile 0.5412 · 2026-10-06
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-08 08:50:52.119177+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-73487.html