VendorsFlowiseAIflowiseall versions
Vulnerabilities

FlowiseAI Flowise

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

128CVEs
CVE-2026-69254
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
Published 2026-08-04 · Analyzed
9.4EPSS 0.007
CVE-2025-71327
Flowise - Authentication Bypass via Unprotected Registration Endpoint
Published 2026-06-25 · Analyzed
9.3EPSS 0.007
CVE-2026-56278
Flowise - Session Hijacking via Weak Default Express Session Secret
Published 2026-06-30 · Analyzed
9.3EPSS 0.005
CVE-2026-69255
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
Published 2026-08-04 · Analyzed
9.2EPSS 0.007
CVE-2026-69258
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
Published 2026-08-04 · Analyzed
9.1EPSS 0.007
CVE-2026-46440
Flowise: Basic Auth Credentials Exposed via API
Published 2026-06-08 · Analyzed
9.1EPSS 0.004
CVE-2026-69251
Flowise RCE via TypeORM DataSource
Published 2026-08-04 · Analyzed
9.0EPSS 0.027
CVE-2026-73601
Flowise before 3.1.3 Remote Code Execution via Custom MCP
Published 2026-08-13 · Analyzed
9.0EPSS 0.011
CVE-2026-69253
Flowise Sandbox Escape to RCE
Published 2026-08-04 · Analyzed
9.0EPSS 0.007
CVE-2026-73486
Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV
Published 2026-08-13 · Analyzed
9.0EPSS 0.007
CVE-2026-73485
Flowise before 3.1.3 Remote Code Execution via Airtable Agent
Published 2026-08-13 · Analyzed
9.0EPSS 0.006
CVE-2025-61687
FlowiseAI/Flosise has File Upload vulnerability
Published 2025-10-06 · Analyzed
8.8EPSS 0.111
CVE-2026-41138
Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas.
Published 2026-04-23 · Modified
8.8EPSS 0.008
CVE-2026-41269
Flowise: File Upload Validation Bypass in createAttachment
Published 2026-04-23 · Modified
8.8EPSS 0.007
CVE-2026-30820
Flowise Authorization Bypass via Spoofed x-request-from Header
Published 2026-03-07 · Analyzed
8.8EPSS 0.006
CVE-2026-46475
Flowise: Assistant create+update mass-assignment allows cross-workspace assistant takeover
Published 2026-06-08 · Analyzed
8.8EPSS 0.006
CVE-2026-46476
Flowise: CustomTemplate create+update mass-assignment allows cross-workspace template takeover
Published 2026-06-08 · Analyzed
8.8EPSS 0.006
CVE-2026-46477
Flowise: Dataset create+update mass-assignment allows cross-workspace dataset takeover
Published 2026-06-08 · Analyzed
8.8EPSS 0.006
CVE-2026-46478
Flowise: DatasetRow create+update mass-assignment allows cross-workspace row takeover
Published 2026-06-08 · Analyzed
8.8EPSS 0.006
CVE-2026-46479
Flowise: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover
Published 2026-06-08 · Analyzed
8.8EPSS 0.006
CVE-2026-46480
Flowise: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover
Published 2026-06-08 · Analyzed
8.8EPSS 0.006
CVE-2026-46444
Flowise: Vector Store No Permission Checks
Published 2026-06-08 · Analyzed
8.8EPSS 0.006
CVE-2026-69252
Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
Published 2026-08-04 · Analyzed
8.8EPSS 0.005
CVE-2025-71332
Flowise - SQL Injection in importChatflows API via chatflow.id Parameter
Published 2026-06-24 · Analyzed
8.8EPSS 0.005
CVE-2026-70472
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
Published 2026-08-04 · Analyzed
8.8EPSS 0.005
CVE-2026-41277
Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
Published 2026-04-23 · Modified
8.8EPSS 0.005
CVE-2026-30823
Flowise: IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration
Published 2026-03-07 · Analyzed
8.8EPSS 0.005
CVE-2025-71328
Flowise - Unverified Password Change via Account Settings
Published 2026-06-25 · Analyzed
8.8EPSS 0.005
CVE-2026-31829
Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access
Published 2026-03-10 · Analyzed
8.8EPSS 0.004
CVE-2026-56270
Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint
Published 2026-06-24 · Analyzed
8.7EPSS 0.020
CVE-2025-71324
Flowise - Arbitrary File Read via chatId Parameter
Published 2026-06-25 · Modified
8.7EPSS 0.016
CVE-2026-71962
Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download
Published 2026-08-10 · Analyzed
8.7EPSS 0.007
CVE-2026-70636
Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint
Published 2026-08-06 · Analyzed
8.7EPSS 0.007
CVE-2026-41278
Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs
Published 2026-04-23 · Analyzed
8.7EPSS 0.004
CVE-2025-71337
Flowise - Unverified Email Change via Account Profile Endpoint
Published 2026-06-23 · Analyzed
8.7EPSS 0.004
CVE-2026-73484
Flowise before 3.1.3 Sandbox Escape via Pandas Methods
Published 2026-08-13 · Analyzed
8.6EPSS 0.004
CVE-2026-69257
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
Published 2026-08-04 · Analyzed
8.6EPSS 0.004
CVE-2025-71335
Flowise - Session Invalidation Failure After Password Change
Published 2026-06-25 · Analyzed
8.6EPSS 0.004
CVE-2026-69250
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
Published 2026-08-04 · Analyzed
8.5EPSS 0.006
CVE-2026-70473
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
Published 2026-08-04 · Analyzed
8.5EPSS 0.005
← Prev2 / 4Next →