Flowiseai

Flowise

146 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht Exploit
  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 11:28:04
  • Zuletzt bearbeitet 03.09.2026 18:59:13

Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit this to exfiltrate uploaded CSV data...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 10.08.2026 18:26:18
  • Zuletzt bearbeitet 04.09.2026 13:54:36

Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attackers to access private files by exploiting the endpoint's inclusion in th...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 08.08.2026 16:03:39
  • Zuletzt bearbeitet 04.09.2026 14:12:04

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadat...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 06.08.2026 22:18:28
  • Zuletzt bearbeitet 15.09.2026 16:02:22

Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in pac...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 06.08.2026 22:18:22
  • Zuletzt bearbeitet 15.09.2026 16:08:16

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissi...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 06.08.2026 22:18:22
  • Zuletzt bearbeitet 15.09.2026 16:07:38

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to...

Medienbericht
  • EPSS 0.44%
  • Veröffentlicht 04.08.2026 20:16:54
  • Zuletzt bearbeitet 11.09.2026 21:09:26

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blockl...

  • EPSS 0.38%
  • Veröffentlicht 04.08.2026 20:16:54
  • Zuletzt bearbeitet 11.09.2026 21:14:26

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The endpoint decr...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 04.08.2026 19:23:57
  • Zuletzt bearbeitet 11.09.2026 21:09:17

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controll...

  • EPSS 0.3%
  • Veröffentlicht 04.08.2026 19:18:44
  • Zuletzt bearbeitet 11.09.2026 21:08:48

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lacks the checkAnyPermission() middleware that protects...