An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint
https://github.com/FlowiseAI/Flowise/blob/main/packages/server/src/utils/validateKey.ts
https://github.com/FlowiseAI/Flowise/blob/main/packages/server/src/utils/constants.ts