Flowiseai

Flowise

125 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.45%
  • Veröffentlicht 10.08.2026 18:26:18
  • Zuletzt bearbeitet 10.08.2026 19:17:31

Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attackers to access private files by exploiting the endpoint's inclusion in th...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 08.08.2026 16:03:39
  • Zuletzt bearbeitet 10.08.2026 14:17:26

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadat...

  • EPSS 0.32%
  • Veröffentlicht 06.08.2026 22:18:28
  • Zuletzt bearbeitet 08.08.2026 03:16:47

Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in pac...

  • EPSS 0.23%
  • Veröffentlicht 06.08.2026 22:18:22
  • Zuletzt bearbeitet 07.08.2026 18:17:21

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissi...

  • EPSS 0.25%
  • Veröffentlicht 06.08.2026 22:18:22
  • Zuletzt bearbeitet 07.08.2026 18:17:21

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to...

  • EPSS 0.44%
  • Veröffentlicht 04.08.2026 20:16:54
  • Zuletzt bearbeitet 05.08.2026 15:17:08

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blockl...

  • EPSS 0.38%
  • Veröffentlicht 04.08.2026 20:16:54
  • Zuletzt bearbeitet 05.08.2026 20:17:16

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The endpoint decr...

  • EPSS 0.29%
  • Veröffentlicht 04.08.2026 19:23:57
  • Zuletzt bearbeitet 05.08.2026 16:17:02

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controll...

  • EPSS 0.3%
  • Veröffentlicht 04.08.2026 19:18:44
  • Zuletzt bearbeitet 04.08.2026 20:16:54

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lacks the checkAnyPermission() middleware that protects...

  • EPSS 0.29%
  • Veröffentlicht 04.08.2026 18:01:01
  • Zuletzt bearbeitet 05.08.2026 15:17:08

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The authorize, callback...