Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw Found in Flowise AI Software

A serious security weakness has been found in Flowise, a tool used to build customised AI chatflows. This flaw could let attackers run harmful commands on the computer hosting the software, potentially leading to data loss or system damage. The issue has been fixed in the latest update.

11 July 2026

Reference: CVE-2026-41264

1. What is being reported?

The vulnerability is in how Flowise processes certain AI-generated scripts without proper safety checks. Attackers can send specially crafted messages that trick the system into running malicious code on the server where Flowise is installed.

2. What this means in plain English

If your organisation uses Flowise, an attacker could take control of the system running it, which might lead to stolen information or disruption of your services. This is a high-risk issue because it allows unauthorised access without needing a password.

3. Could this affect a small business?

Small businesses or charities using Flowise versions before 3.1.0 are at risk. Those not using Flowise or who have updated to the fixed version are unlikely to be affected.

4. What to do now

  • Check if your organisation uses Flowise software, especially versions before 3.1.0.
  • If you use Flowise, update it immediately to version 3.1.0 or later.
  • Limit who can send inputs to your Flowise chatflows to trusted users only.
  • Ask your IT provider to review your systems for any signs of compromise related to this vulnerability.

5. Ask your IT provider

Can you confirm if we use Flowise software and, if so, have we updated it to version 3.1.0 or later to fix the critical security flaw?

6. Bottom line

Update Flowise software promptly to protect your organisation from a serious security risk.

Information based on CISA KEV, NVD, and reputable security reporting.

Back to Vulnerability Briefs