CVE-2025-55346criticalobserved exploitationCWE-94

CVE-2025-55346: critical vulnerability in flowise

Unintended dynamic code execution leads to remote code execution by network attackers

Published

55Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 9.8epss 22%
from disclosure to weapon
Published on NVDAug 14
VulnCheck+97d
exploitation probability
22%top 2% of all CVEs
observed exploitation
yesVulnCheck
User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to run arbitrary unsandboxed JS code in the context of the host, by sending a simple POST request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
flowise