CVE-2026-31829
- EPSS 0.06%
- Veröffentlicht 10.03.2026 21:43:58
- Zuletzt bearbeitet 11.03.2026 14:24:01
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise exposes an HTTP Node in AgentFlow and Chatflow that performs server-side HTTP requests using user-controlled URLs. By default, there are...
CVE-2026-30822
- EPSS 0.2%
- Veröffentlicht 07.03.2026 05:16:27
- Zuletzt bearbeitet 11.03.2026 13:40:13
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauthenticated users can inject arbitrary values into internal database fields when creating leads. This issue has been patched in vers...
CVE-2026-30821
- EPSS 0.14%
- Veröffentlicht 07.03.2026 05:16:26
- Zuletzt bearbeitet 11.03.2026 13:45:38
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId/:chatId endpoint is listed in WHITELIST_URLS, allowing unauthenticated access to the file upload API...
CVE-2026-30820
- EPSS 0.09%
- Veröffentlicht 07.03.2026 05:16:26
- Zuletzt bearbeitet 11.03.2026 13:46:22
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowise trusts any HTTP client that sets the header x-request-from: internal, allowing an authenticated tenant session to bypass all /ap...
CVE-2026-30824
- EPSS 0.04%
- Veröffentlicht 07.03.2026 05:11:15
- Zuletzt bearbeitet 11.03.2026 13:35:41
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvidia-nim/*) is whitelisted in the global authentication middleware, allowing unauthenticated access to ...
CVE-2026-30823
- EPSS 0.02%
- Veröffentlicht 07.03.2026 05:10:08
- Zuletzt bearbeitet 11.03.2026 13:36:25
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue has been pat...
CVE-2025-57164
- EPSS 0.13%
- Veröffentlicht 17.10.2025 00:00:00
- Zuletzt bearbeitet 23.10.2025 12:33:49
Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.
CVE-2025-34267
- EPSS 1.23%
- Veröffentlicht 14.10.2025 19:31:50
- Zuletzt bearbeitet 27.10.2025 19:12:43
Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nod...
CVE-2025-61913
- EPSS 0.71%
- Veröffentlicht 08.10.2025 22:43:24
- Zuletzt bearbeitet 20.10.2025 15:23:05
Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool in Flowise do not restrict file path access, allowing authenticated attackers to exploit this vulnerab...
CVE-2025-61687
- EPSS 0.18%
- Veröffentlicht 06.10.2025 15:54:56
- Zuletzt bearbeitet 16.10.2025 18:12:37
Flowise is a drag & drop user interface to build a customized large language model flow. A file upload vulnerability in version 3.0.7 of FlowiseAI allows authenticated users to upload arbitrary files without proper validation. This enables attackers ...