THREAT OPS › Threat News › [GHSA] GHSA-6vh2-wg4h-4vwj (high) — Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
[GHSA] GHSA-6vh2-wg4h-4vwj (high) — Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
GHSA-6vh2-wg4h-4vwj Severity: high CVE: CVE-2026-69258
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
#### Summary
The `POST /api/v1/prediction/:id` endpoint — which is unauthenticated (whitelisted in `WHITELIST_URLS`) — accepts an `overrideConfig` object in the request body. This object is unconditionally spread int
Indicators of compromise
- CVE-2026-69258cve
- CVE-2026-30822cve
Original source: https://github.com/advisories/GHSA-6vh2-wg4h-4vwj