VendorsFlowiseAIflowiseall versions
Vulnerabilities

FlowiseAI Flowise

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

128CVEs
CVE-2026-70476
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
Published 2026-08-04 · Analyzed
8.3EPSS 0.005
CVE-2026-41271
Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains
Published 2026-04-23 · Analyzed
8.3EPSS 0.003
CVE-2026-41270
Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
Published 2026-04-23 · Modified
8.3EPSS 0.003
CVE-2025-50538
Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.
Published 2025-10-06 · Analyzed
8.2EPSS 0.140
CVE-2026-41273
Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow
Published 2026-04-23 · Modified
8.2EPSS 0.004
CVE-2025-29192
Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.
Published 2025-10-06 · Analyzed
8.2EPSS 0.004
CVE-2026-41279
Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials
Published 2026-04-23 · Analyzed
8.2EPSS 0.004
CVE-2026-69262
Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
Published 2026-08-04 · Analyzed
8.1EPSS 0.005
CVE-2026-70474
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
Published 2026-08-04 · Analyzed
8.1EPSS 0.005
CVE-2026-42863
Flowise: Mass Assignment in Chatflow Update Endpoint Allows Cross-Workspace AgentFlow Reassignment
Published 2026-06-08 · Analyzed
8.1EPSS 0.004
CVE-2026-41266
Flowise: Sensitive Data Leak in public-chatbotConfig
Published 2026-04-23 · Modified
7.7EPSS 0.005
CVE-2026-67620
Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List
Published 2026-08-08 · Analyzed
7.7EPSS 0.005
CVE-2026-30822
Flowise: Mass Assignment in `/api/v1/leads` Endpoint
Published 2026-03-07 · Analyzed
7.7EPSS 0.005
CVE-2026-56268
Flowise - Cross-Workspace Information Disclosure via chatflows/apikey Endpoint
Published 2026-06-22 · Analyzed
7.7EPSS 0.004
CVE-2024-31621
An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.
Published 2024-04-29 · Analyzed
7.61 PoCEPSS 0.599
CVE-2026-67621
Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints
Published 2026-08-06 · Analyzed
7.6EPSS 0.004
CVE-2025-29189
Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores.
Published 2025-04-09 · Analyzed
7.6EPSS 0.003
CVE-2026-42862
Flowise: Mass Assignment in Tool Update Endpoint Allows Cross-Workspace Resource Reassignment
Published 2026-06-08 · Analyzed
7.6EPSS 0.003
CVE-2024-8182
Flowise Denial of Service
Published 2024-08-27 · Analyzed
7.5EPSS 0.139
CVE-2024-36421
GHSL-2023-234: Flowise Cors Misconfiguration in packages/server/src/index.ts
Published 2024-07-01 · Modified
7.5EPSS 0.085
CVE-2025-59527
FlowiseAI/Flowise has Server-Side Request Forgery (SSRF) vulnerability
Published 2025-09-22 · Analyzed
7.5EPSS 0.050
CVE-2024-36420
GHSL-2023-232: Flowise Path Injection at /api/v1/openai-assistants-file
Published 2024-07-01 · Modified
7.5EPSS 0.018
CVE-2026-90535
Flowise before 3.1.4 Denial of Service via text-to-speech/abort
Published 2026-09-12 · Analyzed
7.5EPSS 0.005
CVE-2026-41275
Flowise: Password Reset Link Sent Over Unsecured HTTP
Published 2026-04-23 · Modified
7.5EPSS 0.003
CVE-2026-70475
Flowise: Missing Authorization on Execution Update Endpoint
Published 2026-08-04 · Analyzed
7.1EPSS 0.005
CVE-2026-70471
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
Published 2026-08-04 · Analyzed
7.1EPSS 0.004
CVE-2026-73604
Flowise before 3.1.3 Credential Exposure via API
Published 2026-08-13 · Analyzed
7.1EPSS 0.004
CVE-2026-41272
Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)
Published 2026-04-23 · Analyzed
7.1EPSS 0.004
CVE-2026-56275
Flowise - Server-Side Request Forgery via Execute Flow Base URL
Published 2026-06-23 · Analyzed
7.1EPSS 0.003
CVE-2026-46443
Flowise: Credential Data Leak
Published 2026-06-08 · Analyzed
7.0EPSS 0.004
CVE-2026-56277
Flowise - Hardcoded CORS Wildcard in TTS Endpoint
Published 2026-06-30 · Analyzed
6.9EPSS 0.002
CVE-2025-57164
Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.
Published 2025-10-17 · Analyzed
6.5EPSS 0.006
CVE-2026-90580
FlowiseAI Flowise Evaluations Endpoint index.ts axios.post server-side request forgery
Published 2026-09-13 · Analyzed
6.5EPSS 0.004
CVE-2026-73488
Flowise before 3.1.3 IDOR via customer-default-source endpoint
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-90534
Flowise before 3.1.4 Cross-Workspace Credential IDOR via node-load-method
Published 2026-09-12 · Analyzed
6.5EPSS 0.004
CVE-2026-90533
Flowise before 3.1.4 Broken Access Control via organizationuser
Published 2026-09-12 · Analyzed
6.5EPSS 0.003
CVE-2026-8026
FlowiseAI Flowise API Response account.service.ts login information disclosure
Published 2026-05-06 · Analyzed
6.3EPSS 0.004
CVE-2026-73603
Flowise before 3.1.4 Credential Abuse via Text-to-Speech
Published 2026-08-13 · Analyzed
6.3EPSS 0.003
CVE-2024-37145
GHSL-2023-247: Flowise xss in /api/v1/chatflows-streaming/id
Published 2024-07-01 · Modified
6.1EPSS 0.005
CVE-2024-36422
GHSL-2023-245: Flowise xss in api/v1/chatflows/id
Published 2024-07-01 · Modified
6.1EPSS 0.004
← Prev3 / 4Next →