Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Flowise — Vulnerabilities & Security Advisories 137

All 137 CVE vulnerabilities found in Flowise, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security weaknesses for Flowise, an open-source generative AI workflow automation platform, primarily focusing on server-side request forgery and injection flaws. It collects publicly disclosed advisories spanning from 2023 to the present, covering critical issues such as remote code execution risks in its workflow engine and API endpoints. Here, readers can track the vendor’s historical advisory release patterns, understand the specific class of vulnerabilities affecting this product, and review the full timeline of disclosed defects without navigating between separate databases. The collection emphasizes practical remediation guidance, linking each entry to corresponding patches and version upgrades. By centralizing these records, the page supports security teams in assessing whether a specific release resolves previously identified gaps. No marketing language is used; the focus remains strictly on factual vulnerability data and its evolution over time.

Vendor: FlowiseAI

CVE ID Title CVSS Severity Published
CVE-2025-34267 Flowise Authenticated Command Execution and Sandbox Bypass via Puppeteer & Playwright Packages CWE-77 9.9AI Critical AI 2025-10-14
CVE-2025-61913 Flowise is vulnerable to arbitrary file read, arbitrary file write CWE-22 10.0 Critical 2025-10-08
CVE-2025-61687 FlowiseAI/Flosise has File Upload vulnerability CWE-434 8.3 High 2025-10-06
CVE-2025-29192 Flowise 安全漏洞 CWE-79 8.2 High 2025-10-06
CVE-2025-50538 Flowise 安全漏洞 CWE-79 8.2 High 2025-10-06
CVE-2025-59528 Flowise has Remote Code Execution vulnerability CWE-94 10.0 Critical 2025-09-22
CVE-2025-59527 FlowiseAI/Flowise has Server-Side Request Forgery (SSRF) vulnerability CWE-918 7.5 High 2025-09-22
CVE-2025-59434 Critical Multi-Tenant Variable Disclosure in Flowise Cloud via Custom JavaScript Function CWE-200 9.6 Critical 2025-09-22
CVE-2025-58434 Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover CWE-306 9.8 Critical 2025-09-12
CVE-2024-8181 Flowise Authentication Bypass 9.8 Critical 2024-08-27
CVE-2024-8182 Flowise Denial of Service 7.5 High 2024-08-27
CVE-2024-37146 GHSL-2023-248: Flowise xss in /api/v1/credentials/id CWE-79 6.1 Medium 2024-07-01
CVE-2024-37145 GHSL-2023-247: Flowise xss in /api/v1/chatflows-streaming/id CWE-79 6.1 Medium 2024-07-01
CVE-2024-36423 GHSL-2023-246: Flowise xss in /api/v1/public-chatflows/id CWE-79 6.1 Medium 2024-07-01
CVE-2024-36422 GHSL-2023-245: Flowise xss in api/v1/chatflows/id CWE-79 6.1 Medium 2024-07-01
CVE-2024-36421 GHSL-2023-234: Flowise Cors Misconfiguration in packages/server/src/index.ts CWE-346 7.5 High 2024-07-01
CVE-2024-36420 GHSL-2023-232: Flowise Path Injection at /api/v1/openai-assistants-file CWE-74 7.5 High 2024-07-01

All 137 known CVE vulnerabilities affecting Flowise with full Chinese analysis, references, and POCs where available.