CVE-2026-69258: two ungated spread operators let an unauthenticated caller write into the flow execution context of any public Flowise chatflow.
Source: [HackerNoon](https://hackernoon.com/the-spread-operator-is-an-allowlist-with-nothing-in-it-cve-2026-69258-in-flowise?source=rss)