CVE-2025-55346: critical vulnerability in flowise
Unintended dynamic code execution leads to remote code execution by network attackers
Published
55Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 9.8epss 22%
from disclosure to weapon
Published on NVDAug 14
VulnCheck+97d
exploitation probability
22%top 2% of all CVEs
observed exploitation
yesVulnCheck
User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to run arbitrary unsandboxed JS code in the context of the host, by sending a simple POST request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
flowiseRelated CVEs — flowise
In the same product, most dangerous first.