Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

FlowiseAI — Vulnerabilities & Security Advisories 119

Browse all 119 CVE security advisories affecting FlowiseAI. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FlowiseAI is an open-source platform designed to simplify the development of custom Large Language Model applications by enabling users to construct complex AI workflows through a visual drag-and-drop interface. This accessibility, however, has correlated with a significant security footprint, currently encompassing 43 recorded Common Vulnerabilities and Exposures. Historical analysis reveals that these flaws predominantly stem from insufficient input validation and improper access controls, leading to frequent instances of Remote Code Execution and Cross-Site Scripting. Additionally, several incidents highlight critical privilege escalation risks where authenticated users could bypass intended restrictions to access sensitive system resources. The platform’s modular architecture often introduces supply chain dependencies that further expand the attack surface. While the tool facilitates rapid AI integration, its security posture remains a concern for enterprises, necessitating rigorous patch management and strict network segmentation to mitigate the potential for exploitation in production environments.

Found 118 results / 119 Clear Filters
Top products by FlowiseAI: Flowise FlowiseChatEmbed
CVE ID Title CVSS Severity Published
CVE-2026-41267 Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association — Flowise CWE-639 8.1 High 2026-04-23
CVE-2026-41266 Flowise: Sensitive Data Leak in public-chatbotConfig — Flowise CWE-200 9.1AI Critical AI 2026-04-23
CVE-2026-41137 Flowise: Code Injection in CSVAgent leads to Authenticated RCE — Flowise CWE-94 8.8AI High AI 2026-04-23
CVE-2026-41138 Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas. — Flowise CWE-94 9.8AI Critical AI 2026-04-23
CVE-2026-40933 Flowise: Authenticated RCE Via MCP Adapters — Flowise CWE-78 10.0 Critical 2026-04-21
CVE-2026-31829 Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access — Flowise CWE-918 7.1 High 2026-03-10
CVE-2026-30824 Flowise: Missing Authentication on NVIDIA NIM Endpoints — Flowise CWE-306 10.0 - 2026-03-07
CVE-2026-30823 Flowise: IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration — Flowise CWE-639 8.1 - 2026-03-07
CVE-2026-30822 Flowise: Mass Assignment in `/api/v1/leads` Endpoint — Flowise CWE-915 5.3 - 2026-03-07
CVE-2026-30821 Flowise: Arbitrary File Upload via MIME Spoofing — Flowise CWE-434 9.8 - 2026-03-07
CVE-2026-30820 Flowise Authorization Bypass via Spoofed x-request-from Header — Flowise CWE-863 8.8 - 2026-03-07
CVE-2025-34267 Flowise Authenticated Command Execution and Sandbox Bypass via Puppeteer & Playwright Packages — Flowise CWE-77 8.4 High 2025-10-14
CVE-2025-61913 Flowise is vulnerable to arbitrary file read, arbitrary file write — Flowise CWE-22 10.0 Critical 2025-10-08
CVE-2025-61687 FlowiseAI/Flosise has File Upload vulnerability — Flowise CWE-434 8.3 High 2025-10-06
CVE-2025-29192 Flowise 安全漏洞 — Flowise CWE-79 8.2 High 2025-10-06
CVE-2025-50538 Flowise 安全漏洞 — Flowise CWE-79 8.2 High 2025-10-06
CVE-2025-59528 Flowise has Remote Code Execution vulnerability — Flowise CWE-94 10.0 Critical 2025-09-22
CVE-2025-59527 FlowiseAI/Flowise has Server-Side Request Forgery (SSRF) vulnerability — Flowise CWE-918 7.5 High 2025-09-22
CVE-2025-59434 Critical Multi-Tenant Variable Disclosure in Flowise Cloud via Custom JavaScript Function — Flowise CWE-200 9.6 Critical 2025-09-22
CVE-2025-58434 Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover — Flowise CWE-306 9.8 Critical 2025-09-12
CVE-2024-8181 Flowise Authentication Bypass — Flowise 9.8 Critical 2024-08-27
CVE-2024-8182 Flowise Denial of Service — Flowise 7.5 High 2024-08-27
CVE-2024-37146 GHSL-2023-248: Flowise xss in /api/v1/credentials/id — Flowise CWE-79 6.1 Medium 2024-07-01
CVE-2024-37145 GHSL-2023-247: Flowise xss in /api/v1/chatflows-streaming/id — Flowise CWE-79 6.1 Medium 2024-07-01
CVE-2024-36423 GHSL-2023-246: Flowise xss in /api/v1/public-chatflows/id — Flowise CWE-79 6.1 Medium 2024-07-01
CVE-2024-36422 GHSL-2023-245: Flowise xss in api/v1/chatflows/id — Flowise CWE-79 6.1 Medium 2024-07-01
CVE-2024-36421 GHSL-2023-234: Flowise Cors Misconfiguration in packages/server/src/index.ts — Flowise CWE-346 7.5 High 2024-07-01
CVE-2024-36420 GHSL-2023-232: Flowise Path Injection at /api/v1/openai-assistants-file — Flowise CWE-74 7.5 High 2024-07-01

This page lists every published CVE security advisory associated with FlowiseAI. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.