cbcvebase.

Flowiseai Flowise vulnerabilities

124 known vulnerabilities affecting flowiseai/flowise.

Total CVEs
124
CISA KEV
0
Public exploits
16
Exploited in wild
10
Severity breakdown
CRITICAL43HIGH59MEDIUM21LOW1

Vulnerabilities

Page 7 of 7
CVE-2026-56269P4MEDIUMCVSS 4.6fixed in 3.1.02026-06-24
CVE-2026-56269 [MEDIUM] CWE-798 CVE-2026-56269: Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded defaul Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' for the TOKEN_HASH_SECRET environment variable in packages/server/src/enterprise/utils/tempTokenUtils.ts when the variable is not configured. This secret derives the AES-256-CBC key used to encrypt user IDs and workspace IDs in the '
nvd
CVE-2025-29192P4MEDIUMCVSS 6.1fixed in 3.0.52025-10-06
CVE-2025-29192 [MEDIUM] CWE-79 CVE-2025-29192: Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.
ghsanvdosv
CVE-2026-56272P4MEDIUMCVSS 4.1fixed in 3.0.132026-06-24
CVE-2026-56272 [MEDIUM] CWE-916 CVE-2026-56272: Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instea Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password hashes approximately 30 times faster with modern GPU hardware, potentially compromising all user accounts in a database breach scenario.
nvd
CVE-2026-8028P4LOWCVSS 3.7≤ 3.0.12v3.0.0+12 more2026-05-06
CVE-2026-8028 [LOW] CWE-200 CVE-2026-8028: A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/server/src/enterprise/services/account.service.ts of the component Endpoint. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible. The attack is considered to have high complexity. It i
nvd