cbcvebase.

Flowiseai Flowise vulnerabilities

124 known vulnerabilities affecting flowiseai/flowise.

Total CVEs
124
CISA KEV
0
Public exploits
16
Exploited in wild
10
Severity breakdown
CRITICAL43HIGH59MEDIUM21LOW1

Vulnerabilities

Page 1 of 7
CVE-2025-59528P1CRITICALCVSS 10.0ExploitedPoCv3.0.5v= 3.0.52025-09-22
CVE-2025-59528 [CRITICAL] CWE-94 CVE-2025-59528: Flowise is a drag & drop user interface to build a customized large language model flow. In version Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connecting to an external MCP server. This node parses the user-provided mcpServerConfig string to build the MCP server configur
ghsanvdosv
CVE-2025-8943P1CRITICALCVSS 9.8ExploitedPoCfixed in 3.0.1fixed in 3.1.32025-08-14
CVE-2025-8943 [CRITICAL] CWE-306 CVE-2025-8943: The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise versions before 3.0.1 the default installation operates without authentication
ghsanvdosv
CVE-2025-26319P1CRITICALCVSS 9.8ExploitedPoCv2.2.6≥ 3.0.1, ≤ 3.0.82025-03-04
CVE-2025-26319 [CRITICAL] CWE-434 CVE-2025-26319: FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1 FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
ghsanvdosv
CVE-2026-46442P1CRITICALCVSS 9.9ExploitedPoCfixed in 3.1.22026-06-08
CVE-2026-46442 [CRITICAL] CWE-94 CVE-2026-46442: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to ve Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScript to the Custom JS Function node. When E2B_APIKEY is not configured — the common deployment case —
ghsanvd
CVE-2024-8181P1HIGHCVSS 8.1ExploitedPoCv1.8.22024-08-27
CVE-2024-8181 [HIGH] CWE-287 CVE-2024-8181: An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, u An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.
ghsanvdosv
CVE-2025-71334P1CRITICALCVSS 9.8ExploitedPoCfixed in 3.0.62026-06-25
CVE-2025-71334 [CRITICAL] CWE-73 CVE-2025-71334: Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnera Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations. By supplying a path-traversal value (e.g., '../../../../../tmp') as the chatflow id, an unauthenticated attacker can use the
nvd
CVE-2026-56270P1HIGHCVSS 7.5ExploitedPoCfixed in 3.1.02026-06-24
CVE-2026-56270 [HIGH] CWE-306 CVE-2026-56270: Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability i Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users to retrieve an organization's complete SSO configuration, including OAuth client secrets in cleartext, by providing an organizationId parameter. Remote attackers can send a GET request
nvd
CVE-2025-71324P1HIGHCVSS 7.5ExploitedPoCfixed in 3.0.62026-06-25
CVE-2025-71324 [HIGH] CWE-73 CVE-2025-71324: Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /a Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints. The chatId value is not validated and is passed to streamStorageFile(), where a fallback file-lookup path constructed without the orgId is evaluated after the storage-directory
nvd
CVE-2024-36420P2HIGHCVSS 7.5ExploitedPoCv1.4.3≤ 1.4.32024-07-01
CVE-2024-36420 [HIGH] CWE-74 CVE-2024-36420: Flowise is a drag & drop user interface to build a customized large language model flow. In version Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-file` endpoint in `index.ts` is vulnerable to arbitrary file read due to lack of sanitization of the `fileName` body parameter. No known patches for this issue are available.
ghsanvdosv
CVE-2025-55346P1CRITICALExploited≥ 0, ≤ 2.2.7-patch.12025-10-06
CVE-2025-55346 [CRITICAL] CWE-627 Flowise vulnerable to RCE via Dynamic function constructor injection Flowise vulnerable to RCE via Dynamic function constructor injection ### Summary User-controlled input flows to an unsafe implementaion of a dynamic Function constructor , allowing a malicious actor to run JS code in the context of the host (not sandboxed) leading to RCE. ### Details When creating a new `Custom MCP` Chatflow in the platform, the MCP Server Config displays a placeholder hintin
ghsaosv
CVE-2025-58434P1CRITICALCVSS 9.8PoCfixed in 3.0.6≤ 3.0.52025-09-12
CVE-2025-58434 [CRITICAL] CWE-306 CVE-2025-58434: Flowise is a drag & drop user interface to build a customized large language model flow. In version Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint in Flowise returns sensitive information including a valid password reset `tempToken` without authentication or verification. This enables any attacker to generate a reset token for arbitrary users an
ghsanvdosv
CVE-2026-30824P1CRITICALCVSS 9.8PoCfixed in 3.0.132026-03-07
CVE-2026-30824 [CRITICAL] CWE-306 CVE-2026-30824: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to ve Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvidia-nim/*) is whitelisted in the global authentication middleware, allowing unauthenticated access to privileged container management and token generation endpoints. This issue has been patched in vers
ghsanvdosv
CVE-2024-31621P2HIGHCVSS 7.6PoC≤ 1.6.52024-04-29
CVE-2024-31621 [HIGH] CWE-94 CVE-2024-31621: An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary c An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.
ghsanvdosv
CVE-2026-56274P1CRITICALCVSS 9.9PoCfixed in 3.1.22026-06-23
CVE-2026-56274 [CRITICAL] CWE-78 CVE-2026-56274: Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restrictions. An attacker with a Flowise account of any role, or API access with view/update permissions for chatflows, can configure a malicious MCP server to
nvd
CVE-2026-41264P2CRITICALCVSS 9.8PoCfixed in 3.1.02026-04-23
CVE-2026-41264 [CRITICAL] CWE-184 CVE-2026-41264: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the CSV_Agents class. The issue results from the lack of proper sandboxing when evaluating an LLM generated python script. An attacker can leverage this vulnerability to execute code in the cont
ghsanvd
CVE-2026-69251P2CRITICALCVSS 9.0PoCfixed in 3.1.32026-08-04
CVE-2026-69251 [CRITICAL] CWE-94 CVE-2026-69251: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSource options through the additionalConfig input in packages/components/nodes/recordmanager/MySQLRecordManager/MySQLrecordManager.ts, packages/components/n
ghsanvd
CVE-2026-41268P1CRITICALCVSS 9.8fixed in 3.1.02026-04-23
CVE-2026-41268 [CRITICAL] CWE-20 CVE-2026-41268: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthenticated remote command execution (RCE) vulnerability. It can be exploited via a parameter override bypass using the FILE-STORAGE:: keyword combined with a NODE_OPTIONS environment variable injection. T
nvd
CVE-2026-30821P2CRITICALCVSS 9.8fixed in 3.0.132026-03-07
CVE-2026-30821 [CRITICAL] CWE-434 CVE-2026-30821: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to ve Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId/:chatId endpoint is listed in WHITELIST_URLS, allowing unauthenticated access to the file upload API. While the server validates uploads based on the MIME types defined in chatbotConfig.fullFileUploa
ghsanvdosv
CVE-2026-40933P2CRITICALCVSS 9.9fixed in 3.1.02026-04-21
CVE-2026-40933 [CRITICAL] CWE-78 CVE-2026-40933: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command, achieving command execution. The vulnerability lies in a bug in the input sanitization from the “C
ghsanvd
CVE-2026-41276P2CRITICALCVSS 9.8fixed in 3.1.02026-04-23
CVE-2026-41276 [CRITICAL] CWE-287 CVE-2026-41276: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass authentication on affected installations of FlowiseAI Flowise. Authentication is not required to exploit this vulnerability. The specific flaw exists within the resetPassword method of the Ac
nvd
Flowiseai Flowise vulnerabilities | cvebase