11 July 2026
Reference: CVE-2026-41264
1. What is being reported?
The vulnerability is in how Flowise processes certain AI-generated scripts without proper safety checks. Attackers can send specially crafted messages that trick the system into running malicious code on the server where Flowise is installed.
2. What this means in plain English
If your organisation uses Flowise, an attacker could take control of the system running it, which might lead to stolen information or disruption of your services. This is a high-risk issue because it allows unauthorised access without needing a password.
3. Could this affect a small business?
Small businesses or charities using Flowise versions before 3.1.0 are at risk. Those not using Flowise or who have updated to the fixed version are unlikely to be affected.
4. What to do now
- Check if your organisation uses Flowise software, especially versions before 3.1.0.
- If you use Flowise, update it immediately to version 3.1.0 or later.
- Limit who can send inputs to your Flowise chatflows to trusted users only.
- Ask your IT provider to review your systems for any signs of compromise related to this vulnerability.
5. Ask your IT provider
Can you confirm if we use Flowise software and, if so, have we updated it to version 3.1.0 or later to fix the critical security flaw?
6. Bottom line
Update Flowise software promptly to protect your organisation from a serious security risk.
Information based on CISA KEV, NVD, and reputable security reporting.