Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Flowise — Vulnerabilities & Security Advisories 137

All 137 CVE vulnerabilities found in Flowise, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security weaknesses for Flowise, an open-source generative AI workflow automation platform, primarily focusing on server-side request forgery and injection flaws. It collects publicly disclosed advisories spanning from 2023 to the present, covering critical issues such as remote code execution risks in its workflow engine and API endpoints. Here, readers can track the vendor’s historical advisory release patterns, understand the specific class of vulnerabilities affecting this product, and review the full timeline of disclosed defects without navigating between separate databases. The collection emphasizes practical remediation guidance, linking each entry to corresponding patches and version upgrades. By centralizing these records, the page supports security teams in assessing whether a specific release resolves previously identified gaps. No marketing language is used; the focus remains strictly on factual vulnerability data and its evolution over time.

Vendor: FlowiseAI

CVE ID Title CVSS Severity Published
CVE-2025-71333 Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint CWE-73 - - 2026-06-25
CVE-2025-71328 Flowise - Unverified Password Change via Account Settings CWE-620 8.3 High 2026-06-25
CVE-2025-71327 Flowise - Authentication Bypass via Unprotected Registration Endpoint CWE-306 9.1 Critical 2026-06-25
CVE-2025-71324 Flowise - Arbitrary File Read via chatId Parameter CWE-73 7.5 High 2026-06-25
CVE-2026-56272 Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing CWE-916 4.1 Medium 2026-06-24
CVE-2026-56270 Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint CWE-306 7.5 High 2026-06-24
CVE-2026-56269 Flowise - Weak Default Token Hash Secret in JWT Token Encryption CWE-798 4.6 Medium 2026-06-24
CVE-2025-71332 Flowise - SQL Injection in importChatflows API via chatflow.id Parameter CWE-89 6.5 Medium 2026-06-24
CVE-2026-56274 Flowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess CWE-78 9.9 Critical 2026-06-23
CVE-2026-56275 Flowise - Server-Side Request Forgery via Execute Flow Base URL CWE-918 - - 2026-06-23
CVE-2025-71337 Flowise - Unverified Email Change via Account Profile Endpoint CWE-620 8.3 High 2026-06-23
CVE-2026-56268 Flowise - Cross-Workspace Information Disclosure via chatflows/apikey Endpoint CWE-863 7.7 High 2026-06-22
CVE-2026-12821 FlowiseAI Flowise S3 Document Loader S3.ts path traversal CWE-22 6.3 Medium 2026-06-21
CVE-2026-56276 Flowise - Mass Assignment in PUT /api/v1/user Allows Password Hash Override CWE-915 - - 2026-06-20
CVE-2026-56267 Flowise - PII Disclosure via Unauthenticated Forgot Password Endpoint CWE-200 - - 2026-06-20
CVE-2025-71331 Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows CWE-80 6.1 Medium 2026-06-20
CVE-2024-58351 Flowise - Remote Code Execution via overrideConfig Parameter CWE-94 9.8 Critical 2026-06-20
CVE-2026-46480 Flowise: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover CWE-915 - - 2026-06-08
CVE-2026-46479 Flowise: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover CWE-915 - - 2026-06-08
CVE-2026-46478 Flowise: DatasetRow create+update mass-assignment allows cross-workspace row takeover CWE-915 - - 2026-06-08
CVE-2026-46477 Flowise: Dataset create+update mass-assignment allows cross-workspace dataset takeover CWE-915 - - 2026-06-08
CVE-2026-46476 Flowise: CustomTemplate create+update mass-assignment allows cross-workspace template takeover CWE-915 - - 2026-06-08
CVE-2026-46475 Flowise: Assistant create+update mass-assignment allows cross-workspace assistant takeover CWE-915 - - 2026-06-08
CVE-2026-46443 Flowise: Credential Data Leak CWE-200 - - 2026-06-08
CVE-2026-46442 Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape CWE-94 - - 2026-06-08
CVE-2026-46441 Flowise: Mass Assignment in Assistant Update Endpoint Allows Cross-Workspace Resource Reassignment CWE-284 - - 2026-06-08
CVE-2026-46440 Flowise: Basic Auth Credentials Exposed via API CWE-522 - - 2026-06-08
CVE-2026-42863 Flowise: Mass Assignment in Chatflow Update Endpoint Allows Cross-Workspace AgentFlow Reassignment CWE-284 - - 2026-06-08
CVE-2026-42862 Flowise: Mass Assignment in Tool Update Endpoint Allows Cross-Workspace Resource Reassignment CWE-284 - - 2026-06-08
CVE-2026-42861 Flowise: Mass Assignment in Variable Update Endpoint Allows Cross-Workspace Resource Reassignment CWE-284 - - 2026-06-08

All 137 known CVE vulnerabilities affecting Flowise with full Chinese analysis, references, and POCs where available.