VendorsFlowiseAIflowiseall versions
Vulnerabilities

FlowiseAI Flowise

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

128CVEs
CVE-2025-59528
Flowise has Remote Code Execution vulnerability
Published 2025-09-22 · Analyzed
10.01 PoCEPSS 0.862
CVE-2025-71338
Flowise - Arbitrary File Write to Remote Code Execution via document-store API
Published 2026-06-25 · Modified
10.0EPSS 0.012
CVE-2026-70478
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
Published 2026-08-04 · Analyzed
10.0EPSS 0.006
CVE-2025-61913
Flowise is vulnerable to arbitrary file read, arbitrary file write
Published 2025-10-08 · Analyzed
9.9EPSS 0.130
CVE-2026-56274
Flowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess
Published 2026-06-23 · Analyzed
9.9EPSS 0.075
CVE-2025-34267
Flowise Authenticated Command Execution and Sandbox Bypass via Puppeteer & Playwright Packages
Published 2025-10-14 · Analyzed
9.9EPSS 0.066
CVE-2026-46442
Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
Published 2026-06-08 · Analyzed
9.9EPSS 0.034
CVE-2026-40933
Flowise: Authenticated RCE Via MCP Adapters
Published 2026-04-21 · Analyzed
9.9EPSS 0.013
CVE-2026-73602
Flowise before 3.1.3 Sandbox Escape to RCE
Published 2026-08-13 · Analyzed
9.9EPSS 0.008
CVE-2026-67622
Flowise 3.1.4 IDOR in OpenAI Assistants Integration
Published 2026-08-06 · Analyzed
9.9EPSS 0.005
CVE-2025-8943
Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers
Published 2025-08-14 · Analyzed
9.8EPSS 0.658
CVE-2025-26319
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
Published 2025-03-04 · Analyzed
9.8EPSS 0.559
CVE-2025-58434
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
Published 2025-09-12 · Analyzed
9.81 PoCEPSS 0.499
CVE-2024-8181
Flowise Authentication Bypass
Published 2024-08-27 · Modified
9.8EPSS 0.451
CVE-2025-71334
Flowise - Arbitrary File Access via Missing Chat Flow ID Validation
Published 2026-06-25 · Analyzed
9.8EPSS 0.044
CVE-2026-30824
Flowise: Missing Authentication on NVIDIA NIM Endpoints
Published 2026-03-07 · Analyzed
9.8EPSS 0.026
CVE-2026-41268
Flowise: Flowise Parameter Override Bypass Remote Command Execution
Published 2026-04-23 · Analyzed
9.8EPSS 0.012
CVE-2026-41264
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Published 2026-04-23 · Analyzed
9.8EPSS 0.012
CVE-2025-71336
Flowise - Unsandboxed Remote Code Execution via Custom MCP
Published 2026-06-25 · Analyzed
9.8EPSS 0.011
CVE-2026-52098
An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint
Published 2026-09-10 · Analyzed
9.8EPSS 0.011
CVE-2026-69264
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
Published 2026-08-04 · Analyzed
9.8EPSS 0.011
CVE-2026-70470
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
Published 2026-08-04 · Analyzed
9.8EPSS 0.010
CVE-2025-71333
Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint
Published 2026-06-25 · Analyzed
9.8EPSS 0.009
CVE-2026-30821
Flowise: Arbitrary File Upload via MIME Spoofing
Published 2026-03-07 · Analyzed
9.8EPSS 0.009
CVE-2026-70477
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Published 2026-08-04 · Analyzed
9.8EPSS 0.008
CVE-2026-73487
Flowise before 3.1.3 Prompt Injection RCE via CSV Agent
Published 2026-08-13 · Analyzed
9.8EPSS 0.008
CVE-2026-41274
Flowise: Cypher Injection in GraphCypherQAChain
Published 2026-04-23 · Analyzed
9.8EPSS 0.007
CVE-2026-69263
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
Published 2026-08-04 · Analyzed
9.8EPSS 0.007
CVE-2026-56271
Flowise - Weak Default JWT Secrets in Authentication Middleware
Published 2026-07-12 · Analyzed
9.8EPSS 0.007
CVE-2026-41276
Flowise: AccountService resetPassword Authentication Bypass Vulnerability
Published 2026-04-23 · Modified
9.8EPSS 0.006
CVE-2026-41265
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
Published 2026-04-23 · Analyzed
9.8EPSS 0.006
CVE-2026-43995
Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)
Published 2026-05-11 · Analyzed
9.8EPSS 0.005
CVE-2026-41267
Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association
Published 2026-04-23 · Analyzed
9.8EPSS 0.005
CVE-2024-9148
Flowise Stored Cross-Site Scripting
Published 2024-09-24 · Analyzed
9.6EPSS 0.006
CVE-2026-42861
Flowise: Mass Assignment in Variable Update Endpoint Allows Cross-Workspace Resource Reassignment
Published 2026-06-08 · Analyzed
9.6EPSS 0.004
CVE-2026-46441
Flowise: Mass Assignment in Assistant Update Endpoint Allows Cross-Workspace Resource Reassignment
Published 2026-06-08 · Analyzed
9.6EPSS 0.004
CVE-2026-41137
Flowise: Code Injection in CSVAgent leads to Authenticated RCE
Published 2026-04-23 · Analyzed
9.4EPSS 0.021
CVE-2026-69256
Flowise: Remote Code Execution Vulnerability in CSVAgent
Published 2026-08-04 · Analyzed
9.4EPSS 0.010
CVE-2026-69259
Flowise RCE via SQLite Record Manager Node
Published 2026-08-04 · Analyzed
9.4EPSS 0.008
CVE-2026-73483
Flowise before 3.1.3 Sandbox Escape via Puppeteer
Published 2026-08-13 · Analyzed
9.4EPSS 0.007
1 / 4Next →