Flowise

FlowiseAI · 128 CVEs

CVE-2026-100610
HIGH

Flowise through 3.1.4 Missing Authorization via upsert-history

Sep 26, 2026

CVE-2026-100609
HIGH

Flowise through 3.1.4 Insecure Direct Object Reference via Credential

Sep 26, 2026

CVE-2026-100608
HIGH

Flowise through 3.1.4 Authorization Bypass via BullMQ Dashboard

Sep 26, 2026

CVE-2026-100607
CRITICAL

Flowise through 3.1.4 Authentication Bypass via Email-Only SSO

Sep 26, 2026

CVE-2026-100606
CRITICAL

Flowise through 3.1.4 Authentication Bypass via SSO Email Match

Sep 26, 2026

CVE-2026-100605
HIGH

Flowise through 3.1.4 Missing Authorization via Chat Message Routes

Sep 26, 2026

CVE-2026-91938
HIGH

Flowise before 3.1.4 Server-Side Request Forgery via document loaders

Sep 15, 2026

CVE-2026-91937
HIGH

Flowise before 3.1.4 NoSQL Injection via sessionId

Sep 15, 2026

CVE-2026-91936
HIGH

Flowise before 3.1.4 Script Injection via Docker Workflows

Sep 15, 2026

CVE-2026-91935
HIGH

Flowise before 3.1.4 SSRF and API Key Exfiltration via Chat Model Nodes

Sep 15, 2026

CVE-2026-91934
HIGH

Flowise before 3.1.4 Remote Code Execution via SQL Database Chain

Sep 15, 2026

CVE-2026-91933
HIGH

Flowise before 3.1.4 Authorization Bypass via openai-realtime

Sep 15, 2026

CVE-2026-91932
CRITICAL

Flowise before 3.1.4 Remote Code Execution via cwd Parameter

Sep 15, 2026

CVE-2026-91931
CRITICAL

Flowise before 3.1.4 Remote Code Execution via Custom MCP npx

Sep 15, 2026

CVE-2026-91930
HIGH

Flowise before 3.1.4 Cross-Tenant Organization Admin Takeover

Sep 15, 2026

CVE-2026-91929
HIGH

Flowise before 3.1.4 Cross-Tenant Authorization Bypass

Sep 15, 2026

CVE-2026-90580
MEDIUM

FlowiseAI Flowise Evaluations Endpoint index.ts axios.post server-side request forgery

Sep 13, 2026

CVE-2026-90535
MEDIUM

Flowise before 3.1.4 Denial of Service via text-to-speech/abort

Sep 12, 2026

CVE-2026-90534
MEDIUM

Flowise before 3.1.4 Cross-Workspace Credential IDOR via node-load-method

Sep 12, 2026

CVE-2026-90533
MEDIUM

Flowise before 3.1.4 Broken Access Control via organizationuser

Sep 12, 2026

CVE-2026-52098
CRITICAL

An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoi…

Sep 10, 2026

CVE-2026-73604
HIGH

Flowise before 3.1.3 Credential Exposure via API

Aug 13, 2026

CVE-2026-73603
MEDIUM

Flowise before 3.1.4 Credential Abuse via Text-to-Speech

Aug 13, 2026

CVE-2026-73602
CRITICAL

Flowise before 3.1.3 Sandbox Escape to RCE

Aug 13, 2026

CVE-2026-73601
CRITICAL

Flowise before 3.1.3 Remote Code Execution via Custom MCP

Aug 13, 2026

Showing 1 to 25 of 128 CVEs