VendorsFlowiseAIflowiseany version
Vulnerabilities

FlowiseAI Flowise any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

116CVEs
CVE-2025-71338
Flowise - Arbitrary File Write to Remote Code Execution via document-store API
Published 2026-06-25 · Modified
10.0EPSS 0.012
CVE-2026-70478
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
Published 2026-08-04 · Analyzed
10.0EPSS 0.005
CVE-2026-46442
Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
Published 2026-06-08 · Analyzed
9.9EPSS 0.363
CVE-2025-61913
Flowise is vulnerable to arbitrary file read, arbitrary file write
Published 2025-10-08 · Analyzed
9.9EPSS 0.130
CVE-2026-40933
Flowise: Authenticated RCE Via MCP Adapters
Published 2026-04-21 · Analyzed
9.9EPSS 0.120
CVE-2026-56274
Flowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess
Published 2026-06-23 · Analyzed
9.9EPSS 0.075
CVE-2025-34267
Flowise Authenticated Command Execution and Sandbox Bypass via Puppeteer & Playwright Packages
Published 2025-10-14 · Analyzed
9.9EPSS 0.066
CVE-2026-73602
Flowise before 3.1.3 Sandbox Escape to RCE
Published 2026-08-13 · Analyzed
9.9EPSS 0.008
CVE-2026-67622
Flowise 3.1.4 IDOR in OpenAI Assistants Integration
Published 2026-08-06 · Analyzed
9.9EPSS 0.003
CVE-2025-8943
Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers
Published 2025-08-14 · Analyzed
9.8EPSS 0.658
CVE-2025-58434
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
Published 2025-09-12 · Analyzed
9.81 PoCEPSS 0.499
CVE-2026-30824
Flowise: Missing Authentication on NVIDIA NIM Endpoints
Published 2026-03-07 · Analyzed
9.8EPSS 0.363
CVE-2026-30821
Flowise: Arbitrary File Upload via MIME Spoofing
Published 2026-03-07 · Analyzed
9.8EPSS 0.147
CVE-2026-41268
Flowise: Flowise Parameter Override Bypass Remote Command Execution
Published 2026-04-23 · Analyzed
9.8EPSS 0.138
CVE-2026-41276
Flowise: AccountService resetPassword Authentication Bypass Vulnerability
Published 2026-04-23 · Modified
9.8EPSS 0.069
CVE-2025-71334
Flowise - Arbitrary File Access via Missing Chat Flow ID Validation
Published 2026-06-25 · Analyzed
9.8EPSS 0.044
CVE-2026-41264
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Published 2026-04-23 · Analyzed
9.8EPSS 0.014
CVE-2026-69264
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
Published 2026-08-04 · Analyzed
9.8EPSS 0.012
CVE-2025-71336
Flowise - Unsandboxed Remote Code Execution via Custom MCP
Published 2026-06-25 · Analyzed
9.8EPSS 0.011
CVE-2026-73487
Flowise before 3.1.3 Prompt Injection RCE via CSV Agent
Published 2026-08-13 · Analyzed
9.8EPSS 0.010
CVE-2025-71333
Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint
Published 2026-06-25 · Analyzed
9.8EPSS 0.009
CVE-2026-70470
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
Published 2026-08-04 · Analyzed
9.8EPSS 0.009
CVE-2026-70477
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Published 2026-08-04 · Analyzed
9.8EPSS 0.008
CVE-2026-56271
Flowise - Weak Default JWT Secrets in Authentication Middleware
Published 2026-07-12 · Analyzed
9.8EPSS 0.007
CVE-2026-41265
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
Published 2026-04-23 · Analyzed
9.8EPSS 0.006
CVE-2026-41274
Flowise: Cypher Injection in GraphCypherQAChain
Published 2026-04-23 · Analyzed
9.8EPSS 0.005
CVE-2026-69263
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
Published 2026-08-04 · Analyzed
9.8EPSS 0.005
CVE-2026-43995
Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)
Published 2026-05-11 · Analyzed
9.8EPSS 0.004
CVE-2026-41267
Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association
Published 2026-04-23 · Analyzed
9.8EPSS 0.003
CVE-2024-9148
Flowise Stored Cross-Site Scripting
Published 2024-09-24 · Analyzed
9.6EPSS 0.006
CVE-2026-46441
Flowise: Mass Assignment in Assistant Update Endpoint Allows Cross-Workspace Resource Reassignment
Published 2026-06-08 · Analyzed
9.6EPSS 0.003
CVE-2026-42861
Flowise: Mass Assignment in Variable Update Endpoint Allows Cross-Workspace Resource Reassignment
Published 2026-06-08 · Analyzed
9.6EPSS 0.003
CVE-2026-41137
Flowise: Code Injection in CSVAgent leads to Authenticated RCE
Published 2026-04-23 · Analyzed
9.4EPSS 0.015
CVE-2026-69256
Flowise: Remote Code Execution Vulnerability in CSVAgent
Published 2026-08-04 · Analyzed
9.4EPSS 0.008
CVE-2026-69259
Flowise RCE via SQLite Record Manager Node
Published 2026-08-04 · Analyzed
9.4EPSS 0.007
CVE-2026-69254
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
Published 2026-08-04 · Analyzed
9.4EPSS 0.007
CVE-2026-73483
Flowise before 3.1.3 Sandbox Escape via Puppeteer
Published 2026-08-13 · Analyzed
9.4EPSS 0.006
CVE-2026-56278
Flowise - Session Hijacking via Weak Default Express Session Secret
Published 2026-06-30 · Analyzed
9.3EPSS 0.005
CVE-2026-69255
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
Published 2026-08-04 · Analyzed
9.2EPSS 0.006
CVE-2026-69258
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
Published 2026-08-04 · Analyzed
9.1EPSS 0.005
1 / 3Next →