cbcvebase.

Flowiseai Flowise vulnerabilities

124 known vulnerabilities affecting flowiseai/flowise.

Total CVEs
124
CISA KEV
0
Public exploits
16
Exploited in wild
10
Severity breakdown
CRITICAL43HIGH59MEDIUM21LOW1

Vulnerabilities

Page 3 of 7
CVE-2026-41138P2HIGHCVSS 8.8fixed in 3.1.02026-04-23
CVE-2026-41138 [HIGH] CWE-94 CVE-2026-41138: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas. The user’s input is directly applied to the question parameter within the prompt template and it is reflected to the Python co
ghsanvd
CVE-2025-59434P2CRITICALCVSS 9.6fixed in cloud-hosted (as of Aug 2025)2025-09-22
CVE-2025-59434 [CRITICAL] CWE-200 CVE-2025-59434: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to Au Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Hosted Flowise, an authenticated vulnerability in Flowise Cloud allows any user on the free tier to access sensitive environment variables from other tenants via the Custom JavaScript Function node. This includes secrets such as Open
nvd
CVE-2026-73602P2CRITICALCVSS 9.9fixed in 3.1.32026-08-13
CVE-2026-73602 [CRITICAL] CWE-95 CVE-2026-73602: Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allo Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match function that bypasses path traversal checks to load and execute malicious JavaScript files stored i
nvd
CVE-2026-41274P2CRITICALCVSS 9.8fixed in 3.1.02026-04-23
CVE-2026-41274 [CRITICAL] CWE-943 CVE-2026-41274: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attacker can inject arbitrary Cypher commands that are executed on the underlying Neo4j database, enablin
nvd
CVE-2026-46441P2CRITICALCVSS 9.6fixed in 3.1.22026-06-08
CVE-2026-46441 [CRITICAL] CWE-284 CVE-2026-46441: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to ve Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and updatedDate when updating an assi
ghsanvd
CVE-2026-42861P2CRITICALCVSS 9.6fixed in 3.1.22026-06-08
CVE-2026-42861 [CRITICAL] CWE-284 CVE-2026-42861: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to ve Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the variable update endpoint of FlowiseAI. The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and updatedDate when updating a variab
ghsanvd
CVE-2026-70477P2CRITICALCVSS 9.5fixed in 3.1.22026-08-04
CVE-2026-70477 [CRITICAL] CWE-94 CVE-2026-70477: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment. The specific flaw exists within th
ghsanvd
CVE-2026-41137P2HIGHCVSS 8.8fixed in 3.1.02026-04-23
CVE-2026-41137 [HIGH] CWE-94 CVE-2026-41137: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent allows providing a custom Pandas CSV read code. Due to lack of sanitization, an attacker can provide a command injection payload that will get interpolated and executed by the server. This vulnerability is fixed in 3.1.0.
nvd
CVE-2026-56278P2CRITICALCVSS 9.1fixed in 3.1.02026-06-30
CVE-2026-56278 [CRITICAL] CWE-798 CVE-2026-56278: Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('f Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set (packages/server/src/enterprise/middleware/passport/index.ts). Because this default secret is publicly visible in the source code, an attacke
nvd
CVE-2026-73483P2HIGHCVSS 8.8≤ 3.1.2fixed in 3.1.32026-08-13
CVE-2026-73483 [HIGH] CWE-78 CVE-2026-73483: Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in t Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-custom-function endpoint can escape the sandbox by supplying attacker-controlled executablePath and args parameters to puppeteer.launch(), which internally
nvd
CVE-2026-30820P2HIGHCVSS 8.8fixed in 3.0.132026-03-07
CVE-2026-30820 [HIGH] CWE-863 CVE-2026-30820: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to ve Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowise trusts any HTTP client that sets the header x-request-from: internal, allowing an authenticated tenant session to bypass all /api/v1/** authorization checks. With only a browser cookie, a low-privilege tenant can invoke internal ad
ghsanvdosv
CVE-2024-36421P3HIGHCVSS 7.5v1.4.3≤ 1.4.32024-07-01
CVE-2024-36421 [HIGH] CWE-346 CVE-2024-36421: Flowise is a drag & drop user interface to build a customized large language model flow. In version Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets the Access-Control-Allow-Origin header to all, allowing arbitrary origins to connect to the website. In the default configuration (unauthenticated), arbitrary origins may be able to make requests to Flowise,
ghsanvdosv
CVE-2026-58057P3MEDIUMCVSS 5.0PoCfixed in 3.1.32026-06-28
CVE-2026-58057 [MEDIUM] CWE-178 CVE-2026-58057: Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a cas Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensitive, supplying 'node_options' bypasses the NODE_OPTIONS denylist entry. An authenticated user who can configure a Custom MCP node can thereby inject NODE_OPTIONS --require
nvd
CVE-2026-69256P2CRITICALCVSS 9.4fixed in 3.1.32026-08-04
CVE-2026-69256 [CRITICAL] CWE-94 CVE-2026-69256: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python constructs, pandas.read_pickle() could deserialize a pickled payload and achieve code execution without matchin
ghsanvd
CVE-2026-69259P2CRITICALCVSS 9.4fixed in 3.1.32026-08-04
CVE-2026-69259 [CRITICAL] CWE-94 CVE-2026-69259: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it after the intended database setting, allowing additionalConfig.database
ghsanvd
CVE-2026-69255P3CRITICALCVSS 9.2fixed in 3.1.32026-08-04
CVE-2026-69255 [CRITICAL] CWE-94 CVE-2026-69255: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into executable Python as base64_string = "${base64String}" before calling Pyodi
ghsanvd
CVE-2026-69258P2HIGHCVSS 8.8fixed in 3.1.32026-08-04
CVE-2026-69258 [HIGH] CWE-639 CVE-2026-69258: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in packages/server/src/utils/buildChatflow.ts and packages/server/src/utils/index
ghsanvd
CVE-2026-41269P3HIGHCVSS 8.8fixed in 3.1.02026-04-23
CVE-2026-41269 [HIGH] CWE-434 CVE-2026-41269: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload settings can be modified to allow the application/javascript MIME type. This lets an attacker upload .js files even though the frontend doesn’t normally allow JavaScript uploads. This enables attackers to pers
nvd
CVE-2026-41273P3HIGHCVSS 8.2fixed in 3.1.0≤ 3.1.42026-04-23
CVE-2026-41273 [HIGH] CWE-306 CVE-2026-41273: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass vulnerability that allows an unauthenticated attacker to obtain OAuth 2.0 access tokens associated with a public chatflow. By accessing a public chatflow configuration endpoint, an attacker can retrieve int
nvd
CVE-2026-73486P3HIGHCVSS 8.8fixed in 3.1.32026-08-13
CVE-2026-73486 [HIGH] CWE-94 CVE-2026-73486: Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV p Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a static regex blocklist that can be bypassed through obfuscation techniques, enabling attackers to execute code in the unsandboxed pyodide environment with
nvd
Flowiseai Flowise vulnerabilities | cvebase