Flowiseai

Flowise

125 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 13.08.2026 11:28:10
  • Zuletzt bearbeitet 13.08.2026 15:20:18

Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive data i...

  • EPSS 0.32%
  • Veröffentlicht 13.08.2026 11:28:09
  • Zuletzt bearbeitet 14.08.2026 23:16:33

Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using store...

  • EPSS 0.61%
  • Veröffentlicht 13.08.2026 11:28:08
  • Zuletzt bearbeitet 14.08.2026 21:17:57

Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command ...

  • EPSS 0.44%
  • Veröffentlicht 13.08.2026 11:28:08
  • Zuletzt bearbeitet 13.08.2026 13:19:19

Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match ...

  • EPSS 0.27%
  • Veröffentlicht 13.08.2026 11:28:07
  • Zuletzt bearbeitet 13.08.2026 15:20:15

Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile data by manipu...

  • EPSS 0.33%
  • Veröffentlicht 13.08.2026 11:28:06
  • Zuletzt bearbeitet 13.08.2026 13:19:17

Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a static regex blocklist that can be bypassed throug...

  • EPSS 0.39%
  • Veröffentlicht 13.08.2026 11:28:06
  • Zuletzt bearbeitet 14.08.2026 23:16:33

Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.rea...

  • EPSS 0.28%
  • Veröffentlicht 13.08.2026 11:28:05
  • Zuletzt bearbeitet 14.08.2026 21:17:57

Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques. Attackers ca...

  • EPSS 0.37%
  • Veröffentlicht 13.08.2026 11:28:04
  • Zuletzt bearbeitet 14.08.2026 23:16:33

Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-custom-function endpoint can escape the sandbox by ...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 11:28:04
  • Zuletzt bearbeitet 13.08.2026 15:20:15

Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit this to exfiltrate uploaded CSV data...