Skip to main content

Vendor/product archive

flowiseai / flowise CVEs

Beta · best-effort

86 CVEs tagged to flowiseai / flowise22 Critical, 48 High, 14 Medium, 2 Low, 0 Unrated.

CVE-2026-56271

Published Jul 12, 2026

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIEN…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-56278

Published Jun 30, 2026

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET env…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-56277

Published Jun 30, 2026

Flowise before 3.1.2 sets Access-Control-Allow-Origin to a hardcoded wildcard (*) on its text-to-speech (TTS) generation endpoint (packages/server/src/controllers/text-to-speech/i…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-58057

Published Jun 28, 2026

Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensi…

CVSS 2.3 · Low
evidence mentions
5
Buzz score
38.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-71338

Published Jun 25, 2026

Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesys…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-71336

Published Jun 25, 2026

Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to exec…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-71335

Published Jun 25, 2026

Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already h…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-71334

Published Jun 25, 2026

Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-71333

Published Jun 25, 2026

Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit p…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-71328

Published Jun 25, 2026

Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-71327

Published Jun 25, 2026

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-71324

Published Jun 25, 2026

Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints. Th…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2026-56272

Published Jun 24, 2026

Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password h…

CVSS 5.6 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-56270

Published Jun 24, 2026

Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users to retriev…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-56269

Published Jun 24, 2026

Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' for the TOKEN_HASH_SECRET environment variable in packages/se…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-71332

Published Jun 24, 2026

Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation of the chatflow.id value, an authenticated user can supply…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2026-56275

Published Jun 23, 2026

Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validation by providing intranet addres…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-56274

Published Jun 23, 2026

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-71337

Published Jun 23, 2026

Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authenticated user can change the account email address, used as…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2026-56268

Published Jun 22, 2026

Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endpoint. When the keyonly query parameter is omitted (the default),…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-71331

Published Jun 20, 2026

Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent functions. An attacker can inject…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-46480

Published Jun 8, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluator create and update mass-assignment allows cross-workspace…

CVSS 7.7 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-46479

Published Jun 8, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment allows cross-workspac…

CVSS 7.7 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-46478

Published Jun 8, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, DatasetRow create and update mass-assignment allows cross-workspac…

CVSS 7.7 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-46477

Published Jun 8, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, dataset create and update mass-assignment allows cross-workspace d…

CVSS 7.7 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 86 CVEsPage 1 of 4