Vulnerabilities
CVE-2026-70478
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
CVE-2026-70477
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
GHSA-8gj2-2cvc-6xx7
Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
CVE-2026-70475
Flowise: Missing Authorization on Execution Update Endpoint
CVE-2026-70476
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
CVE-2026-70474
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
CVE-2026-69256
Flowise: Remote Code Execution Vulnerability in CSVAgent
CVE-2026-70471
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
GHSA-88pr-878c-24wf
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
GHSA-rwrp-9823-p2xq
Flowise: Incomplete Credential Redaction Exposes Secrets via API
CVE-2026-70472
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
CVE-2026-70473
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
CVE-2026-69264
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
CVE-2026-70470
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
CVE-2026-69263
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
CVE-2026-69262
Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
CVE-2026-69259
Flowise RCE via SQLite Record Manager Node
CVE-2026-69257
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
CVE-2026-69258
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
CVE-2026-69254
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
CVE-2026-69255
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
CVE-2026-69253
Flowise Sandbox Escape to RCE
CVE-2026-69252
Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
CVE-2026-69251
Flowise RCE via TypeORM DataSource
CVE-2026-69250
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
GHSA-2364-jh4q-m9vm
Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
CVE-2025-71324
Flowise has an Arbitrary File Read
CVE-2026-56269
Flowise: Weak Default Token Hash Secret
CVE-2026-56272
Flowise has Insufficient Password Salt Rounds
CVE-2026-56268
Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows
CVE-2026-56271
Flowise: Weak Default JWT Secrets
CVE-2026-56273
Flowise: Path Traversal in Vector Store basePath
CVE-2026-56267
Flowise Vulnerable to PII Disclosure on Unauthenticated Forgot Password Endpoint
CVE-2026-56277
Flowise: Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpage
CVE-2026-56278
Flowise: Weak Default Express Session Secret
CVE-2026-56274
Flowise has an MCP Security Bypass that Enables RCE
CVE-2026-56276
Flowise: Mass Assignment in PUT /api/v1/user Allows Authenticated Users to Override Password Hash and Bypass Password Change Verification
CVE-2026-56275
Flowise Execute Flow function has an SSRF vulnerability
CVE-2025-50538
Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
CVE-2025-71331
Flowise vulnerable to XSS
CVE-2025-71333
Flowise Pre-auth Arbitrary File Upload
CVE-2025-71336
Flowise has unsandboxed remote code execution via Custom MCP
CVE-2025-71338
Flowise allows arbitrary file write to RCE
CVE-2025-29192
Flowise Stored XSS vulnerability through logs in chatbot
CVE-2025-71334
Flowise has arbitrary file access due to missing chat flow id validation
CVE-2024-58351
Flowise OverrideConfig security vulnerability
CVE-2025-71335
Flowise Fails to Invalidate Existing Sessions After Password Changes
CVE-2025-71327
Flowise has Authentication Bypass Using Unprotected Registration Endpoint (/register)
CVE-2026-46478
FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover
CVE-2026-46477
FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover
CVE-2026-46479
FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover
CVE-2025-71332
FlowiseDB vulnerable to SQL Injection by authenticated users
CVE-2026-56270
Flowise: Unauthenticated Information Disclosure of OAuth Secrets (Cleartext) via GET Request
CVE-2026-46475
FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover
CVE-2026-46444
FlowiseAI: Vector Store No Permission Checks
CVE-2026-46480
FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover
CVE-2026-42862
FlowiseAI has Mass Assignment in Tool Update Endpoint that Allows Cross-Workspace Resource Reassignment
CVE-2026-46442
FlowiseAI: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
CVE-2026-46441
FlowiseAI has Mass Assignment in Assistant Update Endpoint that Allows Cross-Workspace Resource Reassignment
CVE-2026-46440
FlowiseAI Exposes Basic Auth Credentials via API
CVE-2026-46476
FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover
CVE-2026-42863
FlowiseAI has Mass Assignment in Chatflow Update Endpoint that Allows Cross-Workspace AgentFlow Reassignment
CVE-2026-46443
FlowiseAI Vulnerable to Credential Data Leak
CVE-2026-42861
FlowiseAI has Mass Assignment in Variable Update Endpoint that Allows Cross-Workspace Resource Reassignment
CVE-2026-43995
Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)
CVE-2026-8026
Flowise: Bcrypt Password Hash Exposure
CVE-2026-41270
Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
CVE-2026-41275
Flowise: Password Reset Link Sent Over Unsecured HTTP
CVE-2026-41278
Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs
CVE-2026-41265
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
CVE-2026-41269
Flowise: File Upload Validation Bypass in createAttachment
CVE-2026-41276
Flowise: resetPassword Authentication Bypass Vulnerability
CVE-2026-41138
Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.
CVE-2026-41268
Flowise: Parameter Override Bypass Remote Command Execution
CVE-2026-41137
Flowise: Code Injection in CSVAgent leads to Authenticated RCE
CVE-2026-41273
Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow in Flowise
CVE-2026-41271
Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains
CVE-2026-41279
Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials
CVE-2026-41266
Flowise: Sensitive Data Leak in public-chatbotConfig
CVE-2026-41267
Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association
CVE-2026-41277
Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
CVE-2026-41264
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
CVE-2026-41272
Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)
CVE-2026-41274
Flowise: Cypher Injection in GraphCypherQAChain
CVE-2026-40933
Flowise: Authenticated RCE Via MCP Adapters
CVE-2026-31829
Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access
CVE-2026-30824
Flowise Missing Authentication on NVIDIA NIM Endpoints
CVE-2026-30822
Flowise Allows Mass Assignment in `/api/v1/leads` Endpoint
CVE-2026-30823
Flowise has IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration
CVE-2026-30820
Flowise has Authorization Bypass via Spoofed x-request-from Header
CVE-2026-30821
Flowise has Arbitrary File Upload via MIME Spoofing
CVE-2025-61913
Flowise is vulnerable to arbitrary file write through its WriteFileTool
GHSA-j44m-5v8f-gc9c
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
CVE-2025-61687
FlowiseAI/Flosise has File Upload vulnerability
CVE-2025-34267
Flowise: Authenticated Command Execution and Sandbox Bypass via Puppeteer and Playwright Packages
CVE-2025-57164
FlowiseAI Pre-Auth Arbitrary Code Execution
GHSA-3g4j-r53p-22wx
Duplicate Advisory: FlowiseAI Pre-Auth Arbitrary Code Execution
CVE-2025-59528
Flowise has Remote Code Execution vulnerability
GHSA-7rgr-72hp-9wp3
Duplicate Advisory: Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
GHSA-wq95-wr7m-26h4
Duplicate Advisory: Flowise Stored XSS vulnerability through logs in chatbot
Ready to move
Start Securing
Free, no credit card | First findings in minutes