flowise
npm110 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting flowisepage 3 of 3
- CVE-2026-70473HIGHCVSS 8.3EG 8.3✓ Fixed in 3.1.32026-08-04
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting …
- CVE-2026-70474HIGHCVSS 7.6EG 7.6✓ Fixed in 3.1.32026-08-04
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The authoriz…
- CVE-2026-70475HIGHCVSS 7.1EG 7.1✓ Fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lacks the checkAnyPermission() middleware th…
- CVE-2026-70476HIGHCVSS 8.3EG 8.3✓ Fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterpri…
- CVE-2026-70477CRITICALCVSS 9.5EG 9.5✓ Fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses…
- CVE-2026-70478CRITICALCVSS 9.2EG 9.2✓ Fixed in 3.1.32026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The en…
- CVE-2026-73488MEDIUMCVSS 6.0EG 6.0✓ Fixed in 3.1.32026-08-13
Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile dat…
- CVE-2026-73603MEDIUMCVSS 6.3EG 6.3✓ Fixed in 3.1.42026-08-13
Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio …
- CVE-2026-73604MEDIUMCVSS 6.5EG 6.5✓ Fixed in 3.1.32026-08-13
Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensi…
- CVE-2026-8026LOWCVSS 3.7EG 3.72026-05-06
A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/services/account.service.ts of the component API Response Handler. The manipulation results in…
Check whether flowise is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for flowise CVEs against the assets you own.
Start Free Scan →