FlowiseAI Flowise

21 known vulnerabilities in FlowiseAI Flowise, 5 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-100610 CVSS 7.7 high Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permission checks, and…
  • CVE-2026-100609 CVSS 7.6 high Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on the requesting…
  • CVE-2026-100608 CVSS 8.7 high Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode with the dashboard…
  • CVE-2026-100607 CVSS 9.2 critical Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing provider or subject identifier bindings…
  • CVE-2026-100606 CVSS 9.2 critical Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When an SSO…
  • CVE-2026-100605 CVSS 7.5 high Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API keys to read and…
  • CVE-2026-91938 CVSS 7.6 high Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader…
  • CVE-2026-91937 CVSS 8.7 high Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory…
  • CVE-2026-91936 CVSS 8.3 high Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are…
  • CVE-2026-91935 CVSS 8.7 high Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to…
  • CVE-2026-91934 CVSS 8.7 high Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing…
  • CVE-2026-91933 CVSS 7.6 high Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to…
  • CVE-2026-91932 CVSS 9.0 critical Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code…
  • CVE-2026-91931 CVSS 9.0 critical Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute…
  • CVE-2026-91930 CVSS 7.7 high Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated…
  • CVE-2026-91929 CVSS 7.6 high Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership…
  • CVE-2026-90580 CVSS 2.1 low A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file…
  • CVE-2026-90535 CVSS 6.3 medium Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that…
  • CVE-2026-90534 CVSS 6.1 medium Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST…
  • CVE-2026-90533 CVSS 6.0 medium Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated…
  • CVE-2026-70477 CVSS 9.5 critical Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a…