A vulnerability, which was classified as critical, was found in FlowiseAI Flowise and Flowise Components up to 3.1.2. The affected element is an unknown function of the file packages/components/nodes/recordmanager/MySQLRecordManager/MySQLrecordManager.ts of the component Record Manager/Agent Memory. The manipulation of the argument additionalConfig results in code injection.

This vulnerability is reported as CVE-2026-69251. The attack can be launched remotely. No exploit exists.

You should upgrade the affected component.