VendorsFlowiseAIflowiseany version
Vulnerabilities

FlowiseAI Flowise any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

116CVEs
CVE-2026-41279
Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials
Published 2026-04-23 · Analyzed
8.2EPSS 0.004
CVE-2026-69262
Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
Published 2026-08-04 · Analyzed
8.1EPSS 0.005
CVE-2026-70474
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
Published 2026-08-04 · Analyzed
8.1EPSS 0.005
CVE-2026-42863
Flowise: Mass Assignment in Chatflow Update Endpoint Allows Cross-Workspace AgentFlow Reassignment
Published 2026-06-08 · Analyzed
8.1EPSS 0.004
CVE-2026-41266
Flowise: Sensitive Data Leak in public-chatbotConfig
Published 2026-04-23 · Modified
7.7EPSS 0.005
CVE-2026-67620
Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List
Published 2026-08-08 · Analyzed
7.7EPSS 0.005
CVE-2026-30822
Flowise: Mass Assignment in `/api/v1/leads` Endpoint
Published 2026-03-07 · Analyzed
7.7EPSS 0.005
CVE-2026-56268
Flowise - Cross-Workspace Information Disclosure via chatflows/apikey Endpoint
Published 2026-06-22 · Analyzed
7.7EPSS 0.004
CVE-2024-31621
An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.
Published 2024-04-29 · Analyzed
7.61 PoCEPSS 0.599
CVE-2026-67621
Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints
Published 2026-08-06 · Analyzed
7.6EPSS 0.004
CVE-2025-29189
Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores.
Published 2025-04-09 · Analyzed
7.6EPSS 0.003
CVE-2026-42862
Flowise: Mass Assignment in Tool Update Endpoint Allows Cross-Workspace Resource Reassignment
Published 2026-06-08 · Analyzed
7.6EPSS 0.003
CVE-2026-90535
Flowise before 3.1.4 Denial of Service via text-to-speech/abort
Published 2026-09-12 · Analyzed
7.5EPSS 0.005
CVE-2026-41275
Flowise: Password Reset Link Sent Over Unsecured HTTP
Published 2026-04-23 · Modified
7.5EPSS 0.003
CVE-2026-70475
Flowise: Missing Authorization on Execution Update Endpoint
Published 2026-08-04 · Analyzed
7.1EPSS 0.005
CVE-2026-73604
Flowise before 3.1.3 Credential Exposure via API
Published 2026-08-13 · Analyzed
7.1EPSS 0.004
CVE-2026-70471
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
Published 2026-08-04 · Analyzed
7.1EPSS 0.004
CVE-2026-41272
Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)
Published 2026-04-23 · Analyzed
7.1EPSS 0.004
CVE-2026-56275
Flowise - Server-Side Request Forgery via Execute Flow Base URL
Published 2026-06-23 · Analyzed
7.1EPSS 0.003
CVE-2026-46443
Flowise: Credential Data Leak
Published 2026-06-08 · Analyzed
7.0EPSS 0.004
CVE-2026-56277
Flowise - Hardcoded CORS Wildcard in TTS Endpoint
Published 2026-06-30 · Analyzed
6.9EPSS 0.002
CVE-2026-90580
FlowiseAI Flowise Evaluations Endpoint index.ts axios.post server-side request forgery
Published 2026-09-13 · Analyzed
6.5EPSS 0.004
CVE-2026-73488
Flowise before 3.1.3 IDOR via customer-default-source endpoint
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-90534
Flowise before 3.1.4 Cross-Workspace Credential IDOR via node-load-method
Published 2026-09-12 · Analyzed
6.5EPSS 0.004
CVE-2026-90533
Flowise before 3.1.4 Broken Access Control via organizationuser
Published 2026-09-12 · Analyzed
6.5EPSS 0.003
CVE-2026-8026
FlowiseAI Flowise API Response account.service.ts login information disclosure
Published 2026-05-06 · Analyzed
6.3EPSS 0.004
CVE-2026-73603
Flowise before 3.1.4 Credential Abuse via Text-to-Speech
Published 2026-08-13 · Analyzed
6.3EPSS 0.003
CVE-2024-37145
GHSL-2023-247: Flowise xss in /api/v1/chatflows-streaming/id
Published 2024-07-01 · Modified
6.1EPSS 0.005
CVE-2024-37146
GHSL-2023-248: Flowise xss in /api/v1/credentials/id
Published 2024-07-01 · Modified
6.1EPSS 0.004
CVE-2024-36423
GHSL-2023-246: Flowise xss in /api/v1/public-chatflows/id
Published 2024-07-01 · Modified
6.1EPSS 0.004
CVE-2025-71331
Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows
Published 2026-06-20 · Analyzed
6.1EPSS 0.003
CVE-2026-56272
Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing
Published 2026-06-24 · Analyzed
5.6EPSS 0.001
CVE-2026-8027
FlowiseAI Flowise User Controller authorization
Published 2026-05-06 · Analyzed
5.3EPSS 0.004
CVE-2026-58057
Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
Published 2026-06-28 · Analyzed
5.01 PoCEPSS 0.016
CVE-2026-56269
Flowise - Weak Default Token Hash Secret in JWT Token Encryption
Published 2026-06-24 · Analyzed
4.6EPSS 0.001
CVE-2026-8028
FlowiseAI Flowise Endpoint account.service.ts verify information disclosure
Published 2026-05-06 · Analyzed
3.7EPSS 0.005
← Prev3 / 3