Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

FlowiseAI — Vulnerabilities & Security Advisories 119

Browse all 119 CVE security advisories affecting FlowiseAI. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FlowiseAI is an open-source platform designed to simplify the development of custom Large Language Model applications by enabling users to construct complex AI workflows through a visual drag-and-drop interface. This accessibility, however, has correlated with a significant security footprint, currently encompassing 43 recorded Common Vulnerabilities and Exposures. Historical analysis reveals that these flaws predominantly stem from insufficient input validation and improper access controls, leading to frequent instances of Remote Code Execution and Cross-Site Scripting. Additionally, several incidents highlight critical privilege escalation risks where authenticated users could bypass intended restrictions to access sensitive system resources. The platform’s modular architecture often introduces supply chain dependencies that further expand the attack surface. While the tool facilitates rapid AI integration, its security posture remains a concern for enterprises, necessitating rigorous patch management and strict network segmentation to mitigate the potential for exploitation in production environments.

Found 118 results / 119 Clear Filters
Top products by FlowiseAI: Flowise FlowiseChatEmbed
CVE ID Title CVSS Severity Published
CVE-2026-71962 Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download — Flowise CWE-862 7.5 High 2026-08-10
CVE-2026-67620 Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List — Flowise CWE-918 7.7 High 2026-08-08
CVE-2026-70636 Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint — Flowise CWE-862 7.5 High 2026-08-06
CVE-2026-67622 Flowise 3.1.4 IDOR in OpenAI Assistants Integration — Flowise CWE-639 9.9 Critical 2026-08-06
CVE-2026-67621 Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints — Flowise CWE-862 7.6 High 2026-08-06
CVE-2026-70478 Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service — Flowise CWE-200 9.2 Critical 2026-08-04
CVE-2026-70477 Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability — Flowise CWE-94 9.5 Critical 2026-08-04
CVE-2026-70476 Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation — Flowise CWE-284 8.3 High 2026-08-04
CVE-2026-70475 Flowise: Missing Authorization on Execution Update Endpoint — Flowise CWE-862 7.1 High 2026-08-04
CVE-2026-70474 Flowise: Cross-Workspace OAuth2 Credential Metadata Leak — Flowise CWE-863 7.6 High 2026-08-04
CVE-2026-70473 Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history — Flowise CWE-200 8.3 High 2026-08-04
CVE-2026-70472 Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store — Flowise CWE-285 7.1 High 2026-08-04
CVE-2026-70471 Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure — Flowise CWE-863 7.1 High 2026-08-04
CVE-2026-70470 Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE — Flowise CWE-184 9.5 Critical 2026-08-04
CVE-2026-69264 Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation — Flowise CWE-94 9.4 Critical 2026-08-04
CVE-2026-69263 Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE) — Flowise CWE-184 8.7 High 2026-08-04
CVE-2026-69262 Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type — Flowise CWE-863 7.1 High 2026-08-04
CVE-2026-69259 Flowise RCE via SQLite Record Manager Node — Flowise CWE-94 9.4 Critical 2026-08-04
CVE-2026-69258 Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API — Flowise CWE-639 8.8 High 2026-08-04
CVE-2026-69257 Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses — Flowise CWE-918 7.6 High 2026-08-04
CVE-2026-69256 Flowise: Remote Code Execution Vulnerability in CSVAgent — Flowise CWE-94 9.4 Critical 2026-08-04
CVE-2026-69255 Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified — Flowise CWE-94 9.2 Critical 2026-08-04
CVE-2026-69254 Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override — Flowise CWE-94 9.4 Critical 2026-08-04
CVE-2026-69253 Flowise Sandbox Escape to RCE — Flowise CWE-95 9.0 Critical 2026-08-04
CVE-2026-69252 Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization — Flowise CWE-862 7.2 High 2026-08-04
CVE-2026-69251 Flowise RCE via TypeORM DataSource — Flowise CWE-94 9.0 Critical 2026-08-04
CVE-2026-69250 Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration — Flowise CWE-639 8.5 High 2026-08-04
CVE-2026-12821 FlowiseAI Flowise S3 Document Loader S3.ts path traversal — Flowise CWE-22 6.3 Medium 2026-06-21
CVE-2026-46480 Flowise: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover — Flowise CWE-915 - - 2026-06-08
CVE-2026-46479 Flowise: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover — Flowise CWE-915 - - 2026-06-08

This page lists every published CVE security advisory associated with FlowiseAI. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.