CVE-2026-52098: Flowise Flowise vulnerability
Published Sep 10, 2026
·Updated
An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint
Affected Software
1 affected component
Flowise Flowise=3.1.2
Event History
Sep 10, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Flowise 3.1.2 deployments where a remote attacker can reach the /api/v1/prediction/<flowId> endpoint are the deployments described as affected.
2
Does an attacker need valid credentials or other prerequisites?
The available information identifies the endpoint and states that exploitation is remote, but it does not specify whether authentication, a known flow ID, or any other prerequisite is required.