Flowiseai Flowise vulnerabilities
124 known vulnerabilities affecting flowiseai/flowise.
Total CVEs
124
CISA KEV
0
Public exploits
16
Exploited in wild
10
Severity breakdown
CRITICAL43HIGH59MEDIUM21LOW1
Vulnerabilities
Page 6 of 7
CVE-2026-12821P3MEDIUMCVSS 6.3v3.1.0v3.1.1+1 more2026-06-22
CVE-2026-12821 [MEDIUM] CWE-22 CVE-2026-12821: A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown
A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/documentloaders/S3/S3.ts of the component S3 Document Loader. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The vendor was contacted early about this dis
nvd
CVE-2026-70471P3HIGHCVSS 7.1fixed in 3.1.32026-08-04
CVE-2026-70471 [HIGH] CWE-863 CVE-2026-70471: Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows.
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protected Variables API. Variables for the active workspace are fetched at packages/components/src/utils.ts and runtime varia
ghsanvd
CVE-2025-57164P3MEDIUMCVSS 6.5v3.0.52025-10-17
CVE-2025-57164 [MEDIUM] CWE-77 CVE-2025-57164: Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user inp
Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.
ghsanvdosv
CVE-2026-73488P3MEDIUMCVSS 6.5fixed in 3.1.32026-08-13
CVE-2026-73488 [MEDIUM] CWE-639 CVE-2026-73488: Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /
Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile data by manipulating the customerId parameter. Attackers can enumerate predictable customer IDs to retrieve sensiti
nvd
CVE-2026-73604P3MEDIUMCVSS 6.5fixed in 3.1.32026-08-13
CVE-2026-73604 [MEDIUM] CWE-200 CVE-2026-73604: Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/cr
Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive data including database connection URLs with embedded passwords, cloud service account JSON with private ke
nvd
CVE-2026-46443P3MEDIUMCVSS 6.5fixed in 3.1.22026-06-08
CVE-2026-46443 [MEDIUM] CWE-200 CVE-2026-46443: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to ve
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with a credentialName filter parameter, the encryptedData field is not stripped from the response. The code properly omits encryptedData when no filter is used but fails to do so when a filter is used. This is
ghsanvd
CVE-2026-70472P3HIGHCVSS 7.1fixed in 3.1.32026-08-04
CVE-2026-70472 [HIGH] CWE-285 CVE-2026-70472: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without checking whether that credential belongs to the caller workspace. Route permissions assistants:* only check feature
ghsanvd
CVE-2026-56277P3MEDIUMCVSS 6.5fixed in 3.1.22026-06-30
CVE-2026-56277 [MEDIUM] CWE-346 CVE-2026-56277: Flowise before 3.1.2 sets Access-Control-Allow-Origin to a hardcoded wildcard (*) on its text-to-spe
Flowise before 3.1.2 sets Access-Control-Allow-Origin to a hardcoded wildcard (*) on its text-to-speech (TTS) generation endpoint (packages/server/src/controllers/text-to-speech/index.ts), independent of the server's configured CORS policy. This bypasses the server's otherwise restrictive default CORS configuration (getCorsOptions()) and allows any
nvd
CVE-2026-69262P3HIGHCVSS 7.1fixed in 3.1.32026-08-04
CVE-2026-69262 [HIGH] CWE-863 CVE-2026-69262: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permission was sufficient to reach the delete path. The delete logic then resolved the target record only by i
ghsanvd
CVE-2025-50538P3MEDIUMCVSS 6.1fixed in 3.0.52025-10-06
CVE-2025-50538 [MEDIUM] CWE-79 CVE-2025-50538: Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.
Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.
ghsanvdosv
CVE-2026-73603P3MEDIUMCVSS 5.3fixed in 3.1.42026-08-13
CVE-2026-73603 [MEDIUM] CWE-862 CVE-2026-73603: Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech end
Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API keys by providing a valid chatflow UUID, incurring costs on the chatflow o
nvd
CVE-2026-8026P4MEDIUMCVSS 5.3≤ 3.0.12v3.0.0+12 more2026-05-06
CVE-2026-8026 [MEDIUM] CWE-200 CVE-2026-8026: A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Logi
A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/services/account.service.ts of the component API Response Handler. The manipulation results in information disclosure. The attack can be launched remotely. A high complexity level is associated with this atta
ghsanvd
CVE-2026-42862P4MEDIUMCVSS 5.0fixed in 3.1.22026-06-08
CVE-2026-42862 [MEDIUM] CWE-284 CVE-2026-42862: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to ve
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the tool update endpoint of FlowiseAI. The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and updatedDate when updating a tool resourc
ghsanvd
CVE-2024-37145P4MEDIUMCVSS 6.1≤ 1.4.32024-07-01
CVE-2024-37145 [MEDIUM] CWE-79 CVE-2024-37145: Flowise is a drag & drop user interface to build a customized large language model flow. In version
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting vulnerability occurs in the `/api/v1/chatflows-streaming/id` endpoint. If the default configuration is used (unauthenticated), an attacker may be able to craft a specially crafted URL that injects Javas
ghsanvdosv
CVE-2024-37146P4MEDIUMCVSS 6.1≤ 1.4.32024-07-01
CVE-2024-37146 [MEDIUM] CWE-79 CVE-2024-37146: Flowise is a drag & drop user interface to build a customized large language model flow. In version
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting vulnerability occurs in the `/api/v1/credentials/id` endpoint. If the default configuration is used (unauthenticated), an attacker may be able to craft a specially crafted URL that injects Javascript in
ghsanvdosv
CVE-2024-36423P4MEDIUMCVSS 6.1≤ 1.4.32024-07-01
CVE-2024-36423 [MEDIUM] CWE-79 CVE-2024-36423: Flowise is a drag & drop user interface to build a customized large language model flow. In version
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting vulnerability occurs in the `/api/v1/public-chatflows/id` endpoint. If the default configuration is used (unauthenticated), an attacker may be able to craft a specially crafted URL that injects Javascri
ghsanvdosv
CVE-2024-36422P4MEDIUMCVSS 6.1v1.4.3≤ 1.4.32024-07-01
CVE-2024-36422 [MEDIUM] CWE-79 CVE-2024-36422: Flowise is a drag & drop user interface to build a customized large language model flow. In version
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting vulnerability occurs in the `api/v1/chatflows/id` endpoint. If the default configuration is used (unauthenticated), an attacker may be able to craft a specially crafted URL that injects Javascript into
ghsanvdosv
CVE-2025-71331P4MEDIUMCVSS 6.1fixed in 3.0.82026-06-20
CVE-2025-71331 [MEDIUM] CWE-80 CVE-2025-71331: Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient inpu
Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent functions. An attacker can inject malicious JavaScript by sending an iframe payload (e.g., ) in a chat box, or by having a custom agent function return an XSS payload from an external website. The injected
nvd
CVE-2024-9148P4MEDIUMCVSS 6.1fixed in 2.1.12024-09-25
CVE-2024-9148 [MEDIUM] CWE-79 CVE-2024-9148: Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization i
Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.
ghsanvdosv
CVE-2026-8027P4MEDIUMCVSS 4.3≤ 3.0.12v3.0.0+12 more2026-05-06
CVE-2026-8027 [MEDIUM] CWE-285 CVE-2026-8027: A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is
A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functionality of the component User Controller Handler. This manipulation of the argument userId/organizationId/workspaceId/email causes authorization bypass. The attack may be initiated remotely. The affected component should be upgraded.
nvd