CVE-2026-56270
- EPSS 0.38%
- Veröffentlicht 24.06.2026 11:53:14
- Zuletzt bearbeitet 25.06.2026 14:26:57
Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users to retrieve an organization's complete SSO configuration, including OAuth client ...
CVE-2026-56275
- EPSS 0.2%
- Veröffentlicht 23.06.2026 12:13:01
- Zuletzt bearbeitet 25.06.2026 18:39:37
Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validation by providing intranet addresses through the base URL field. Attackers can initiate HTTP requests to...
CVE-2026-56274
- EPSS 1.66%
- Veröffentlicht 23.06.2026 12:13:00
- Zuletzt bearbeitet 25.06.2026 18:39:19
Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restrictions. An attacker with a Flowise account of any rol...
CVE-2025-71337
- EPSS 0.28%
- Veröffentlicht 23.06.2026 12:12:52
- Zuletzt bearbeitet 25.06.2026 18:38:38
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authenticated user can change the account email address, used as a login identifier and password-recovery channel, via the account profi...
CVE-2026-56268
- EPSS 0.26%
- Veröffentlicht 22.06.2026 21:04:45
- Zuletzt bearbeitet 25.06.2026 16:50:57
Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endpoint. When the keyonly query parameter is omitted (the default), the endpoint returns not only the chatflows bound to the supplied API k...
CVE-2026-12821
- EPSS 0.34%
- Veröffentlicht 21.06.2026 23:15:08
- Zuletzt bearbeitet 22.06.2026 18:24:24
A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/documentloaders/S3/S3.ts of the component S3 Document Loader. Executing a manipulation can lead to path...
CVE-2025-71331
- EPSS 0.16%
- Veröffentlicht 20.06.2026 15:24:39
- Zuletzt bearbeitet 23.06.2026 17:53:02
Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent functions. An attacker can inject malicious JavaScript by sending an iframe payload (e.g., <iframe src="...
CVE-2026-46480
- EPSS 0.34%
- Veröffentlicht 08.06.2026 15:32:15
- Zuletzt bearbeitet 09.06.2026 14:57:08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluator create and update mass-assignment allows cross-workspace evaluator takeover. This issue has been patched in version 3.1.2.
CVE-2026-46479
- EPSS 0.34%
- Veröffentlicht 08.06.2026 15:32:03
- Zuletzt bearbeitet 15.06.2026 13:56:30
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment allows cross-workspace evaluation takeover. This issue has been patched in version 3.1.2.
CVE-2026-46478
- EPSS 0.34%
- Veröffentlicht 08.06.2026 15:31:55
- Zuletzt bearbeitet 15.06.2026 13:58:37
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, DatasetRow create and update mass-assignment allows cross-workspace row takeover. This issue has been patched in version 3.1.2.