Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Flowise — Vulnerabilities & Security Advisories 137

All 137 CVE vulnerabilities found in Flowise, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security weaknesses for Flowise, an open-source generative AI workflow automation platform, primarily focusing on server-side request forgery and injection flaws. It collects publicly disclosed advisories spanning from 2023 to the present, covering critical issues such as remote code execution risks in its workflow engine and API endpoints. Here, readers can track the vendor’s historical advisory release patterns, understand the specific class of vulnerabilities affecting this product, and review the full timeline of disclosed defects without navigating between separate databases. The collection emphasizes practical remediation guidance, linking each entry to corresponding patches and version upgrades. By centralizing these records, the page supports security teams in assessing whether a specific release resolves previously identified gaps. No marketing language is used; the focus remains strictly on factual vulnerability data and its evolution over time.

Vendor: FlowiseAI

CVE ID Title CVSS Severity Published
CVE-2026-46444 Flowise: Vector Store No Permission Checks CWE-862 - - 2026-06-08
CVE-2026-43995 Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure) CWE-918 - - 2026-05-11
CVE-2026-8028 FlowiseAI Flowise Endpoint account.service.ts verify information disclosure CWE-200 3.7 Low 2026-05-06
CVE-2026-8027 FlowiseAI Flowise User Controller authorization CWE-639 4.3 Medium 2026-05-06
CVE-2026-8026 FlowiseAI Flowise API Response account.service.ts login information disclosure CWE-200 3.7 Low 2026-05-06
CVE-2026-41274 Flowise: Cypher Injection in GraphCypherQAChain CWE-943 9.8AI Critical AI 2026-04-23
CVE-2026-41264 Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability CWE-184 9.8AI Critical AI 2026-04-23
CVE-2026-41265 Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability CWE-77 9.6AI Critical AI 2026-04-23
CVE-2026-41279 Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials CWE-639 8.2AI High AI 2026-04-23
CVE-2026-41278 Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs CWE-200 7.5AI High AI 2026-04-23
CVE-2026-41276 Flowise: AccountService resetPassword Authentication Bypass Vulnerability CWE-287 7.4AI High AI 2026-04-23
CVE-2026-41277 Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR) CWE-284 8.8AI High AI 2026-04-23
CVE-2026-41275 Flowise: Password Reset Link Sent Over Unsecured HTTP CWE-319 6.8AI Medium AI 2026-04-23
CVE-2026-41273 Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow CWE-306 7.5AI High AI 2026-04-23
CVE-2026-41271 Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains CWE-918 8.6AI High AI 2026-04-23
CVE-2026-41272 Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure) CWE-918 7.1 High 2026-04-23
CVE-2026-41270 Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox CWE-284 7.1 High 2026-04-23
CVE-2026-41269 Flowise: File Upload Validation Bypass in createAttachment CWE-434 7.1 High 2026-04-23
CVE-2026-41268 Flowise: Flowise Parameter Override Bypass Remote Command Execution CWE-20 9.8AI Critical AI 2026-04-23
CVE-2026-41267 Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association CWE-639 8.1 High 2026-04-23
CVE-2026-41266 Flowise: Sensitive Data Leak in public-chatbotConfig CWE-200 9.1AI Critical AI 2026-04-23
CVE-2026-41137 Flowise: Code Injection in CSVAgent leads to Authenticated RCE CWE-94 8.8AI High AI 2026-04-23
CVE-2026-41138 Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas. CWE-94 9.8AI Critical AI 2026-04-23
CVE-2026-40933 Flowise: Authenticated RCE Via MCP Adapters CWE-78 10.0 Critical 2026-04-21
CVE-2026-31829 Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access CWE-918 7.1 High 2026-03-10
CVE-2026-30824 Flowise: Missing Authentication on NVIDIA NIM Endpoints CWE-306 10.0 - 2026-03-07
CVE-2026-30823 Flowise: IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration CWE-639 8.1 - 2026-03-07
CVE-2026-30822 Flowise: Mass Assignment in `/api/v1/leads` Endpoint CWE-915 5.3 - 2026-03-07
CVE-2026-30821 Flowise: Arbitrary File Upload via MIME Spoofing CWE-434 9.8 - 2026-03-07
CVE-2026-30820 Flowise Authorization Bypass via Spoofed x-request-from Header CWE-863 8.8 - 2026-03-07

All 137 known CVE vulnerabilities affecting Flowise with full Chinese analysis, references, and POCs where available.