flowise
npm112 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting flowisepage 2 of 3
- CVE-2026-41273HIGHCVSS 8.2EG 8.2fixed in 3.1.02026-04-23
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass vulnerability that allows an unauthenticated attacker to obtain OAuth 2.0 access tokens asso…
- CVE-2026-41274CRITICALCVSS 9.8EG 9.8fixed in 3.1.02026-04-23
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization…
- CVE-2026-41275HIGHCVSS 7.5EG 7.5fixed in 3.1.02026-04-23
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on cloud.flowiseai.com sends a reset password link over the unsecured HTTP protocol instead of HTTPS.…
- CVE-2026-41276CRITICALCVSS 9.8EG 9.8fixed in 3.1.02026-04-23
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass authentication on affected installations of FlowiseAI Flowise. Authentication is …
- CVE-2026-41277HIGHCVSS 8.8EG 8.8fixed in 3.1.02026-04-23
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated users to control the primary key (id) and …
- CVE-2026-41278HIGHCVSS 7.5EG 7.5fixed in 3.1.02026-04-23
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1/public-chatflows/:id endpoint returns the full chatflow object without sanitization for public chatflows. Docker valid…
- CVE-2026-41279HIGHCVSS 7.5EG 7.5fixed in 3.1.02026-04-23
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-speech generation endpoint (POST /api/v1/text-to-speech/generate) is whitelisted (no auth) and accepts a credentialId dire…
- CVE-2026-42861CRITICALCVSS 9.6EG 9.6fixed in 3.1.22026-06-08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the variable update endpoint of FlowiseAI. The endpoint allows authenticated users t…
- CVE-2026-42862MEDIUMCVSS 5.0EG 5.0fixed in 3.1.22026-06-08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the tool update endpoint of FlowiseAI. The endpoint allows authenticated users to mo…
- CVE-2026-42863HIGHCVSS 8.1EG 8.1fixed in 3.1.22026-06-08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the chatflow update endpoint of FlowiseAI. The endpoint allows clients to modify ser…
- CVE-2026-43995CRITICALCVSS 9.8EG 9.8fixed in 3.1.02026-05-11
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool implementations directly import and invoke raw HTTP clients (node-fetch, axios) instead of using the secured wrapper. Th…
- CVE-2026-46440CRITICALCVSS 9.1EG 9.1fixed in 3.1.22026-06-08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison. This issue ha…
- CVE-2026-46441CRITICALCVSS 9.6EG 9.6fixed in 3.1.22026-06-08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. The endpoint allows authenticated users …
- CVE-2026-46442CRITICALCVSS 9.9EG 9.9fixed in 3.1.22026-06-08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or API key to submit arbitr…
- CVE-2026-46443MEDIUMCVSS 6.5EG 6.5fixed in 3.1.22026-06-08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with a credentialName filter parameter, the encryptedData field is not stripped from the response…
- CVE-2026-46444HIGHCVSS 8.8EG 8.8fixed in 3.1.22026-06-08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRUD endpoints for OpenAI Assistants Vector Store have no authentication middleware and the route path /api/v1/openai-assi…
- CVE-2026-46475HIGHCVSS 8.8EG 8.8fixed in 3.1.22026-06-08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, assistant create and update mass-assignment allows cross-workspace assistant takeover. This issue has been patched in version …
- CVE-2026-46476HIGHCVSS 8.8EG 8.8fixed in 3.1.22026-06-08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomTemplate create and update mass-assignment allows cross-workspace template takeover. This issue has been patched in vers…
- CVE-2026-46477HIGHCVSS 8.8EG 8.8fixed in 3.1.22026-06-08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, dataset create and update mass-assignment allows cross-workspace dataset takeover. This issue has been patched in version 3.1.…
- CVE-2026-46478HIGHCVSS 8.8EG 8.8fixed in 3.1.22026-06-08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, DatasetRow create and update mass-assignment allows cross-workspace row takeover. This issue has been patched in version 3.1.2.
- CVE-2026-46479HIGHCVSS 8.8EG 8.8fixed in 3.1.22026-06-08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment allows cross-workspace evaluation takeover. This issue has been patched in versio…
- CVE-2026-46480HIGHCVSS 8.8EG 8.8fixed in 3.1.22026-06-08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluator create and update mass-assignment allows cross-workspace evaluator takeover. This issue has been patched in version …
- CVE-2026-56267MEDIUMCVSS 6.9EG 6.9fixed in 3.0.132026-06-20
Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoint that returns full user objects including PII to unauthenticated attackers. An attacker can enumerate valid email addr…
- CVE-2026-56268HIGHCVSS 7.7EG 7.7fixed in 3.1.22026-05-20
Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endpoint. When the keyonly query parameter is omitted (the default), the endpoint returns not only the chatflows bound to the sup…
- CVE-2026-56269MEDIUMCVSS 4.6EG 4.6fixed in 3.1.02026-04-16
Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' for the TOKEN_HASH_SECRET environment variable in packages/server/src/enterprise/utils/tempTokenUtils.ts when the variabl…
- CVE-2026-56270HIGHCVSS 7.5EG 7.5fixed in 3.1.02026-04-16
Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users to retrieve an organization's complete SSO configuration, including OA…
- CVE-2026-56271CRITICALCVSS 9.8EG 9.8fixed in 3.1.02026-07-12
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication mid…
- CVE-2026-56272MEDIUMCVSS 4.1EG 4.1fixed in 3.0.132026-03-05
Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password hashes approximately 30 times faster with modern GPU hardware…
- CVE-2026-56273MEDIUMCVSS 6.5EG 6.5fixed in 3.1.02026-07-08
Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that accept unsanitized basePath parameters from authenticated users. Attackers with valid API tokens can write vector store…
- CVE-2026-56274CRITICALCVSS 9.9EG 9.9fixed in 3.1.22026-06-23
Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restrictions. An attacker with a Flowise account…
- CVE-2026-56275HIGHCVSS 7.1EG 7.1fixed in 3.1.02026-06-23
Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validation by providing intranet addresses through the base URL field. Attackers can initiate HTTP …
- CVE-2026-56276MEDIUMCVSS 6.0EG 6.0fixed in 3.1.22026-06-20
Flowise before 3.1.2 contains a mass assignment vulnerability in the PUT /api/v1/user endpoint that allows authenticated users to directly modify the credential field without validation. Attackers can bypass password change verification an…
- CVE-2026-56277MEDIUMCVSS 6.5EG 6.5fixed in 3.1.22026-07-01
Flowise before 3.1.2 sets Access-Control-Allow-Origin to a hardcoded wildcard (*) on its text-to-speech (TTS) generation endpoint (packages/server/src/controllers/text-to-speech/index.ts), independent of the server's configured CORS policy…
- CVE-2026-56278CRITICALCVSS 9.1EG 9.1fixed in 3.1.02026-07-01
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set (packages/server/src/enterprise…
- CVE-2026-69250HIGHCVSS 7.5EG 7.5fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is unauthenticated by design and performs a ser…
- CVE-2026-69251HIGHCVSS 8.8EG 8.8fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSource options through the additionalConfig i…
- CVE-2026-69252HIGHCVSS 8.8EG 8.8fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only by the feat:files feature gate and did not enforce checkPermission on GET or DELETE. A low-…
- CVE-2026-69253HIGHCVSS 8.8EG 8.8fixed in 3.1.32026-08-04
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process vm2�…
- CVE-2026-69254HIGHCVSS 8.8EG 8.8fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged them over the default NodeVM security settings in packages/c…
- CVE-2026-69255HIGHCVSS 8.8EG 8.8fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop(…
- CVE-2026-69256HIGHCVSS 8.8EG 8.8fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python …
- CVE-2026-69257HIGHCVSS 8.6EG 8.6fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.25…
- CVE-2026-69258CRITICALCVSS 9.1EG 9.1fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal…
- CVE-2026-69259HIGHCVSS 8.8EG 8.8fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-con…
- CVE-2026-69262HIGHCVSS 8.1EG 8.1fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of eit…
- CVE-2026-69263CRITICALCVSS 9.8EG 9.8fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, …
- CVE-2026-69264CRITICALCVSS 9.8EG 9.8fixed in 3.1.32026-08-04
Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to glob…
- CVE-2026-70470CRITICALCVSS 9.8EG 9.8fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identi…
- CVE-2026-70471MEDIUMCVSS 6.5EG 6.5fixed in 3.1.32026-08-04
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protected …
- CVE-2026-70472HIGHCVSS 8.8EG 8.8fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without ch…
Check whether flowise is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for flowise CVEs against the assets you own.
Book a Demo →