Flowiseai

Flowise

73 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Veröffentlicht 08.06.2026 15:25:24
  • Zuletzt bearbeitet 11.06.2026 04:08:59

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRUD endpoints for OpenAI Assistants Vector Store have no authentication middleware and the route path /api/v1/openai-assistants-vect...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 11.05.2026 18:16:37
  • Zuletzt bearbeitet 20.05.2026 18:41:54

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool implementations directly import and invoke raw HTTP clients (node-fetch, axios) instead of using the secured wrapper. These tools i...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 06.05.2026 14:15:10
  • Zuletzt bearbeitet 07.05.2026 14:47:19

A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/server/src/enterprise/services/account.service.ts of the component Endpoint. Performing a manipulation results in information disclo...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 06.05.2026 13:45:10
  • Zuletzt bearbeitet 07.05.2026 14:50:57

A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functionality of the component User Controller Handler. This manipulation of the argument userId/organizationId/workspaceId/email causes au...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 06.05.2026 12:30:11
  • Zuletzt bearbeitet 07.05.2026 15:04:56

A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/services/account.service.ts of the component API Response Handler. The manipulation results in informatio...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 23.04.2026 21:12:51
  • Zuletzt bearbeitet 04.05.2026 18:33:02

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attack...

Exploit
  • EPSS 0.53%
  • Veröffentlicht 23.04.2026 20:00:19
  • Zuletzt bearbeitet 24.04.2026 15:15:17

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the CSV_Agents class. The issue results from the lack of proper sandboxing when evaluating an L...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 23.04.2026 19:58:51
  • Zuletzt bearbeitet 24.04.2026 15:15:09

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the Airtable_Agents class. The issue results from the lack of proper sandboxing when evaluating...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 23.04.2026 19:53:15
  • Zuletzt bearbeitet 24.04.2026 16:31:36

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-speech generation endpoint (POST /api/v1/text-to-speech/generate) is whitelisted (no auth) and accepts a credentialId directly in the...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 23.04.2026 19:52:20
  • Zuletzt bearbeitet 24.04.2026 16:31:51

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1/public-chatflows/:id endpoint returns the full chatflow object without sanitization for public chatflows. Docker validation revea...