Flowiseai

Flowise

146 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.79%
  • Veröffentlicht 10.09.2026 00:00:00
  • Zuletzt bearbeitet 15.09.2026 19:09:25

An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint

Exploit
  • EPSS 0.28%
  • Veröffentlicht 13.08.2026 11:28:10
  • Zuletzt bearbeitet 04.09.2026 19:39:50

Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive data i...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 13.08.2026 11:28:09
  • Zuletzt bearbeitet 04.09.2026 19:38:59

Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using store...

Medienbericht
  • EPSS 0.61%
  • Veröffentlicht 13.08.2026 11:28:08
  • Zuletzt bearbeitet 04.09.2026 19:33:58

Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command ...

Medienbericht Exploit
  • EPSS 0.44%
  • Veröffentlicht 13.08.2026 11:28:08
  • Zuletzt bearbeitet 04.09.2026 19:35:03

Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match ...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 13.08.2026 11:28:07
  • Zuletzt bearbeitet 03.09.2026 18:39:03

Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile data by manipu...

Medienbericht Exploit
  • EPSS 0.33%
  • Veröffentlicht 13.08.2026 11:28:06
  • Zuletzt bearbeitet 03.09.2026 18:48:11

Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a static regex blocklist that can be bypassed throug...

Medienbericht Exploit
  • EPSS 0.39%
  • Veröffentlicht 13.08.2026 11:28:06
  • Zuletzt bearbeitet 03.09.2026 18:42:20

Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.rea...

Medienbericht Exploit
  • EPSS 0.28%
  • Veröffentlicht 13.08.2026 11:28:05
  • Zuletzt bearbeitet 03.09.2026 18:51:02

Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques. Attackers ca...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 13.08.2026 11:28:04
  • Zuletzt bearbeitet 03.09.2026 19:00:14

Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-custom-function endpoint can escape the sandbox by ...