Flowiseai

Flowise

146 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 26.09.2026 13:22:52
  • Zuletzt bearbeitet 28.09.2026 19:16:43

Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permission checks, and the backing service performs no workspace or ownership validation. getAllUpsertHistory() returns UpsertHistory ro...

  • EPSS 0.28%
  • Veröffentlicht 26.09.2026 13:22:51
  • Zuletzt bearbeitet 05.10.2026 16:17:02

Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode with the dashboard enabled and not in cloud mode (MODE=queue, ENABLE_BULLMQ_DASHBOARD=true, and !isCloud()), the /admin/queues moun...

  • EPSS 0.23%
  • Veröffentlicht 26.09.2026 13:22:51
  • Zuletzt bearbeitet 30.09.2026 13:17:15

Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on the requesting user's workspace (findOneBy({ id: credentialId }) with no workspaceId condition) in several code paths: getAllOpena...

  • EPSS 0.29%
  • Veröffentlicht 26.09.2026 13:22:50
  • Zuletzt bearbeitet 28.09.2026 18:17:14

Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing provider or subject identifier bindings, allowing attackers to authenticate as any existing user by claiming their email at any configured SSO provider. Attac...

  • EPSS 0.22%
  • Veröffentlicht 26.09.2026 13:22:49
  • Zuletzt bearbeitet 30.09.2026 13:17:15

Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API keys to read and delete chat history. Attackers with valid but low-privileged API keys can access GET and DELETE chat message route...

  • EPSS 0.37%
  • Veröffentlicht 26.09.2026 13:22:49
  • Zuletzt bearbeitet 28.09.2026 19:16:43

Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When an SSO callback arrives with an email matching a user whose status is INVITED, verifyAndLogin (SSOBase.ts:80-94) copies th...

  • EPSS 0.35%
  • Veröffentlicht 15.09.2026 15:18:00
  • Zuletzt bearbeitet 17.09.2026 20:18:53

Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services...

  • EPSS 0.35%
  • Veröffentlicht 15.09.2026 15:17:59
  • Zuletzt bearbeitet 17.09.2026 15:16:57

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharact...

  • EPSS 0.28%
  • Veröffentlicht 15.09.2026 15:17:59
  • Zuletzt bearbeitet 23.09.2026 17:17:47

Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat hist...

  • EPSS 0.28%
  • Veröffentlicht 15.09.2026 15:17:58
  • Zuletzt bearbeitet 20.09.2026 01:16:33

Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys ...