Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

FlowiseAI — Vulnerabilities & Security Advisories 119

Browse all 119 CVE security advisories affecting FlowiseAI. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FlowiseAI is an open-source platform designed to simplify the development of custom Large Language Model applications by enabling users to construct complex AI workflows through a visual drag-and-drop interface. This accessibility, however, has correlated with a significant security footprint, currently encompassing 43 recorded Common Vulnerabilities and Exposures. Historical analysis reveals that these flaws predominantly stem from insufficient input validation and improper access controls, leading to frequent instances of Remote Code Execution and Cross-Site Scripting. Additionally, several incidents highlight critical privilege escalation risks where authenticated users could bypass intended restrictions to access sensitive system resources. The platform’s modular architecture often introduces supply chain dependencies that further expand the attack surface. While the tool facilitates rapid AI integration, its security posture remains a concern for enterprises, necessitating rigorous patch management and strict network segmentation to mitigate the potential for exploitation in production environments.

Top products by FlowiseAI: Flowise FlowiseChatEmbed
CVE ID Title CVSS Severity Published
CVE-2026-46478 Flowise: DatasetRow create+update mass-assignment allows cross-workspace row takeover — Flowise CWE-915 - - 2026-06-08
CVE-2026-46477 Flowise: Dataset create+update mass-assignment allows cross-workspace dataset takeover — Flowise CWE-915 - - 2026-06-08
CVE-2026-46476 Flowise: CustomTemplate create+update mass-assignment allows cross-workspace template takeover — Flowise CWE-915 - - 2026-06-08
CVE-2026-46475 Flowise: Assistant create+update mass-assignment allows cross-workspace assistant takeover — Flowise CWE-915 - - 2026-06-08
CVE-2026-46443 Flowise: Credential Data Leak — Flowise CWE-200 - - 2026-06-08
CVE-2026-46442 Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape — Flowise CWE-94 - - 2026-06-08
CVE-2026-46441 Flowise: Mass Assignment in Assistant Update Endpoint Allows Cross-Workspace Resource Reassignment — Flowise CWE-284 - - 2026-06-08
CVE-2026-46440 Flowise: Basic Auth Credentials Exposed via API — Flowise CWE-522 - - 2026-06-08
CVE-2026-42863 Flowise: Mass Assignment in Chatflow Update Endpoint Allows Cross-Workspace AgentFlow Reassignment — Flowise CWE-284 - - 2026-06-08
CVE-2026-42862 Flowise: Mass Assignment in Tool Update Endpoint Allows Cross-Workspace Resource Reassignment — Flowise CWE-284 - - 2026-06-08
CVE-2026-42861 Flowise: Mass Assignment in Variable Update Endpoint Allows Cross-Workspace Resource Reassignment — Flowise CWE-284 - - 2026-06-08
CVE-2026-46444 Flowise: Vector Store No Permission Checks — Flowise CWE-862 - - 2026-06-08
CVE-2026-43995 Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure) — Flowise CWE-918 - - 2026-05-11
CVE-2026-8028 FlowiseAI Flowise Endpoint account.service.ts verify information disclosure — Flowise CWE-200 3.7 Low 2026-05-06
CVE-2026-8027 FlowiseAI Flowise User Controller authorization — Flowise CWE-639 4.3 Medium 2026-05-06
CVE-2026-8026 FlowiseAI Flowise API Response account.service.ts login information disclosure — Flowise CWE-200 3.7 Low 2026-05-06
CVE-2026-41274 Flowise: Cypher Injection in GraphCypherQAChain — Flowise CWE-943 9.8AI Critical AI 2026-04-23
CVE-2026-41264 Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability — Flowise CWE-184 9.8AI Critical AI 2026-04-23
CVE-2026-41265 Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability — Flowise CWE-77 9.6AI Critical AI 2026-04-23
CVE-2026-41279 Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials — Flowise CWE-639 8.2AI High AI 2026-04-23
CVE-2026-41278 Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs — Flowise CWE-200 7.5AI High AI 2026-04-23
CVE-2026-41276 Flowise: AccountService resetPassword Authentication Bypass Vulnerability — Flowise CWE-287 7.4AI High AI 2026-04-23
CVE-2026-41277 Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR) — Flowise CWE-284 8.8AI High AI 2026-04-23
CVE-2026-41275 Flowise: Password Reset Link Sent Over Unsecured HTTP — Flowise CWE-319 6.8AI Medium AI 2026-04-23
CVE-2026-41273 Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow — Flowise CWE-306 7.5AI High AI 2026-04-23
CVE-2026-41271 Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains — Flowise CWE-918 8.6AI High AI 2026-04-23
CVE-2026-41272 Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure) — Flowise CWE-918 7.1 High 2026-04-23
CVE-2026-41270 Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox — Flowise CWE-284 7.1 High 2026-04-23
CVE-2026-41269 Flowise: File Upload Validation Bypass in createAttachment — Flowise CWE-434 7.1 High 2026-04-23
CVE-2026-41268 Flowise: Flowise Parameter Override Bypass Remote Command Execution — Flowise CWE-20 9.8AI Critical AI 2026-04-23

This page lists every published CVE security advisory associated with FlowiseAI. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.