VendorsFlowiseAIflowiseany version
Vulnerabilities

FlowiseAI Flowise any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

116CVEs
CVE-2026-46440
Flowise: Basic Auth Credentials Exposed via API
Published 2026-06-08 · Analyzed
9.1EPSS 0.004
CVE-2026-69251
Flowise RCE via TypeORM DataSource
Published 2026-08-04 · Analyzed
9.0EPSS 0.027
CVE-2026-73601
Flowise before 3.1.3 Remote Code Execution via Custom MCP
Published 2026-08-13 · Analyzed
9.0EPSS 0.011
CVE-2026-69253
Flowise Sandbox Escape to RCE
Published 2026-08-04 · Analyzed
9.0EPSS 0.007
CVE-2026-73486
Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV
Published 2026-08-13 · Analyzed
9.0EPSS 0.007
CVE-2026-73485
Flowise before 3.1.3 Remote Code Execution via Airtable Agent
Published 2026-08-13 · Analyzed
9.0EPSS 0.006
CVE-2026-41138
Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas.
Published 2026-04-23 · Modified
8.8EPSS 0.008
CVE-2026-41269
Flowise: File Upload Validation Bypass in createAttachment
Published 2026-04-23 · Modified
8.8EPSS 0.007
CVE-2026-30820
Flowise Authorization Bypass via Spoofed x-request-from Header
Published 2026-03-07 · Analyzed
8.8EPSS 0.006
CVE-2026-46478
Flowise: DatasetRow create+update mass-assignment allows cross-workspace row takeover
Published 2026-06-08 · Analyzed
8.8EPSS 0.006
CVE-2026-46475
Flowise: Assistant create+update mass-assignment allows cross-workspace assistant takeover
Published 2026-06-08 · Analyzed
8.8EPSS 0.006
CVE-2026-46476
Flowise: CustomTemplate create+update mass-assignment allows cross-workspace template takeover
Published 2026-06-08 · Analyzed
8.8EPSS 0.006
CVE-2026-46477
Flowise: Dataset create+update mass-assignment allows cross-workspace dataset takeover
Published 2026-06-08 · Analyzed
8.8EPSS 0.006
CVE-2026-46479
Flowise: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover
Published 2026-06-08 · Analyzed
8.8EPSS 0.006
CVE-2026-46480
Flowise: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover
Published 2026-06-08 · Analyzed
8.8EPSS 0.006
CVE-2026-46444
Flowise: Vector Store No Permission Checks
Published 2026-06-08 · Analyzed
8.8EPSS 0.006
CVE-2026-69252
Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
Published 2026-08-04 · Analyzed
8.8EPSS 0.005
CVE-2025-71332
Flowise - SQL Injection in importChatflows API via chatflow.id Parameter
Published 2026-06-24 · Analyzed
8.8EPSS 0.005
CVE-2026-70472
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
Published 2026-08-04 · Analyzed
8.8EPSS 0.005
CVE-2026-41277
Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
Published 2026-04-23 · Modified
8.8EPSS 0.005
CVE-2026-30823
Flowise: IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration
Published 2026-03-07 · Analyzed
8.8EPSS 0.005
CVE-2025-71328
Flowise - Unverified Password Change via Account Settings
Published 2026-06-25 · Analyzed
8.8EPSS 0.005
CVE-2026-31829
Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access
Published 2026-03-10 · Analyzed
8.8EPSS 0.004
CVE-2026-56270
Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint
Published 2026-06-24 · Analyzed
8.7EPSS 0.020
CVE-2025-71324
Flowise - Arbitrary File Read via chatId Parameter
Published 2026-06-25 · Modified
8.7EPSS 0.016
CVE-2026-71962
Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download
Published 2026-08-10 · Analyzed
8.7EPSS 0.007
CVE-2026-70636
Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint
Published 2026-08-06 · Analyzed
8.7EPSS 0.007
CVE-2026-41278
Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs
Published 2026-04-23 · Analyzed
8.7EPSS 0.004
CVE-2025-71337
Flowise - Unverified Email Change via Account Profile Endpoint
Published 2026-06-23 · Analyzed
8.7EPSS 0.004
CVE-2026-73484
Flowise before 3.1.3 Sandbox Escape via Pandas Methods
Published 2026-08-13 · Analyzed
8.6EPSS 0.004
CVE-2026-69257
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
Published 2026-08-04 · Analyzed
8.6EPSS 0.004
CVE-2025-71335
Flowise - Session Invalidation Failure After Password Change
Published 2026-06-25 · Analyzed
8.6EPSS 0.004
CVE-2026-69250
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
Published 2026-08-04 · Analyzed
8.5EPSS 0.006
CVE-2026-70473
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
Published 2026-08-04 · Analyzed
8.5EPSS 0.005
CVE-2026-70476
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
Published 2026-08-04 · Analyzed
8.3EPSS 0.005
CVE-2026-41271
Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains
Published 2026-04-23 · Analyzed
8.3EPSS 0.003
CVE-2026-41270
Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
Published 2026-04-23 · Modified
8.3EPSS 0.003
CVE-2025-50538
Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.
Published 2025-10-06 · Analyzed
8.2EPSS 0.140
CVE-2026-41273
Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow
Published 2026-04-23 · Modified
8.2EPSS 0.004
CVE-2025-29192
Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.
Published 2025-10-06 · Analyzed
8.2EPSS 0.004
← Prev2 / 3Next →