Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Flowise — Vulnerabilities & Security Advisories 25

Browse all 25 CVE security advisories affecting Flowise. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates vulnerability data for the Flowise product, focusing on software weaknesses and specific threat vectors associated with its architecture. It collects security advisories and disclosed flaws impacting the platform, covering a historical timeline from initial public releases through the most recent updates. Users can utilize this resource to track vendor-specific advisories, understand the prevalence of particular weakness classes within the ecosystem, or review the complete vulnerability history of the product. By consolidating these records, the page offers a structured view of security risks, allowing developers and security professionals to assess exposure without manually cross-referencing multiple disparate sources. The data highlights how the product has addressed emerging threats over time, providing context for both past incidents and current defensive postures. This aggregation serves as a reference point for organizations evaluating the reliability of Flowise in their deployment environments, ensuring that security teams have immediate access to relevant technical details and remediation guidance. The focus remains strictly on factual reporting of identified vulnerabilities, enabling efficient risk management and informed decision-making regarding software maintenance and patching strategies for all interested stakeholders.

Top products by Flowise: Flowise
CVE ID Title CVSS Severity Published
CVE-2026-56271 Flowise - Weak Default JWT Secrets in Authentication Middleware — Flowise CWE-321 9.8 Critical 2026-07-12
CVE-2026-56273 Flowise - Path Traversal in Vector Store basePath Parameter — Flowise CWE-22 6.5 Medium 2026-07-08
CVE-2026-56278 Flowise - Session Hijacking via Weak Default Express Session Secret — Flowise CWE-798 9.1 Critical 2026-06-30
CVE-2026-56277 Flowise - Hardcoded CORS Wildcard in TTS Endpoint — Flowise CWE-346 - - 2026-06-30
CVE-2026-58057 Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity — Flowise CWE-178 5.0 Medium 2026-06-28
CVE-2025-71336 Flowise - Unsandboxed Remote Code Execution via Custom MCP — Flowise CWE-78 9.8 Critical 2026-06-25
CVE-2025-71338 Flowise through 2.2.7 - Arbitrary File Write to Remote Code Execution via document-store API — Flowise CWE-73 10.0 Critical 2026-06-25
CVE-2025-71335 Flowise - Session Invalidation Failure After Password Change — Flowise CWE-613 8.1 High 2026-06-25
CVE-2025-71334 Flowise - Arbitrary File Access via Missing Chat Flow ID Validation — Flowise CWE-73 9.8 Critical 2026-06-25
CVE-2025-71333 Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint — Flowise CWE-73 - - 2026-06-25
CVE-2025-71328 Flowise - Unverified Password Change via Account Settings — Flowise CWE-620 8.3 High 2026-06-25
CVE-2025-71327 Flowise - Authentication Bypass via Unprotected Registration Endpoint — Flowise CWE-306 9.1 Critical 2026-06-25
CVE-2025-71324 Flowise - Arbitrary File Read via chatId Parameter — Flowise CWE-73 7.5 High 2026-06-25
CVE-2026-56272 Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing — Flowise CWE-916 4.1 Medium 2026-06-24
CVE-2026-56270 Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint — Flowise CWE-306 7.5 High 2026-06-24
CVE-2026-56269 Flowise - Weak Default Token Hash Secret in JWT Token Encryption — Flowise CWE-798 4.6 Medium 2026-06-24
CVE-2025-71332 Flowise - SQL Injection in importChatflows API via chatflow.id Parameter — Flowise CWE-89 6.5 Medium 2026-06-24
CVE-2026-56274 Flowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess — Flowise CWE-78 9.9 Critical 2026-06-23
CVE-2026-56275 Flowise - Server-Side Request Forgery via Execute Flow Base URL — Flowise CWE-918 - - 2026-06-23
CVE-2025-71337 Flowise - Unverified Email Change via Account Profile Endpoint — Flowise CWE-620 8.3 High 2026-06-23
CVE-2026-56268 Flowise - Cross-Workspace Information Disclosure via chatflows/apikey Endpoint — Flowise CWE-863 7.7 High 2026-06-22
CVE-2026-56276 Flowise - Mass Assignment in PUT /api/v1/user Allows Password Hash Override — Flowise CWE-915 - - 2026-06-20
CVE-2026-56267 Flowise - PII Disclosure via Unauthenticated Forgot Password Endpoint — Flowise CWE-200 - - 2026-06-20
CVE-2025-71331 Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows — Flowise CWE-80 6.1 Medium 2026-06-20
CVE-2024-58351 Flowise - Remote Code Execution via overrideConfig Parameter — Flowise CWE-94 9.8 Critical 2026-06-20

This page lists every published CVE security advisory associated with Flowise. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.