CVE-2026-46444
- EPSS 0.33%
- Veröffentlicht 08.06.2026 15:25:24
- Zuletzt bearbeitet 11.06.2026 04:08:59
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRUD endpoints for OpenAI Assistants Vector Store have no authentication middleware and the route path /api/v1/openai-assistants-vect...
CVE-2026-43995
- EPSS 0.4%
- Veröffentlicht 11.05.2026 18:16:37
- Zuletzt bearbeitet 20.05.2026 18:41:54
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool implementations directly import and invoke raw HTTP clients (node-fetch, axios) instead of using the secured wrapper. These tools i...
CVE-2026-8028
- EPSS 0.4%
- Veröffentlicht 06.05.2026 14:15:10
- Zuletzt bearbeitet 07.05.2026 14:47:19
A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/server/src/enterprise/services/account.service.ts of the component Endpoint. Performing a manipulation results in information disclo...
CVE-2026-8027
- EPSS 0.29%
- Veröffentlicht 06.05.2026 13:45:10
- Zuletzt bearbeitet 07.05.2026 14:50:57
A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functionality of the component User Controller Handler. This manipulation of the argument userId/organizationId/workspaceId/email causes au...
CVE-2026-8026
- EPSS 0.26%
- Veröffentlicht 06.05.2026 12:30:11
- Zuletzt bearbeitet 07.05.2026 15:04:56
A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/services/account.service.ts of the component API Response Handler. The manipulation results in informatio...
CVE-2026-41274
- EPSS 0.5%
- Veröffentlicht 23.04.2026 21:12:51
- Zuletzt bearbeitet 04.05.2026 18:33:02
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attack...
CVE-2026-41264
- EPSS 0.53%
- Veröffentlicht 23.04.2026 20:00:19
- Zuletzt bearbeitet 24.04.2026 15:15:17
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the CSV_Agents class. The issue results from the lack of proper sandboxing when evaluating an L...
CVE-2026-41265
- EPSS 0.46%
- Veröffentlicht 23.04.2026 19:58:51
- Zuletzt bearbeitet 24.04.2026 15:15:09
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the Airtable_Agents class. The issue results from the lack of proper sandboxing when evaluating...
CVE-2026-41279
- EPSS 0.26%
- Veröffentlicht 23.04.2026 19:53:15
- Zuletzt bearbeitet 24.04.2026 16:31:36
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-speech generation endpoint (POST /api/v1/text-to-speech/generate) is whitelisted (no auth) and accepts a credentialId directly in the...
CVE-2026-41278
- EPSS 0.42%
- Veröffentlicht 23.04.2026 19:52:20
- Zuletzt bearbeitet 24.04.2026 16:31:51
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1/public-chatflows/:id endpoint returns the full chatflow object without sanitization for public chatflows. Docker validation revea...