Flowiseai

Flowise

73 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 6.87%
  • Veröffentlicht 23.04.2026 19:49:26
  • Zuletzt bearbeitet 24.04.2026 19:17:11

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass authentication on affected installations of FlowiseAI Flowise. Authentication is not require...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 23.04.2026 19:48:57
  • Zuletzt bearbeitet 25.04.2026 02:16:02

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated users to control the primary key (id) and internal st...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 23.04.2026 19:33:44
  • Zuletzt bearbeitet 25.04.2026 02:16:02

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on cloud.flowiseai.com sends a reset password link over the unsecured HTTP protocol instead of HTTPS. This behav...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 23.04.2026 19:29:16
  • Zuletzt bearbeitet 24.04.2026 19:17:11

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass vulnerability that allows an unauthenticated attacker to obtain OAuth 2.0 access tokens associated with...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 23.04.2026 19:17:40
  • Zuletzt bearbeitet 24.04.2026 16:37:54

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) vulnerability exists in FlowiseAI's POST/GET API Chain components that allows unauthenticated attackers to f...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 23.04.2026 19:16:08
  • Zuletzt bearbeitet 24.04.2026 16:37:31

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core security wrappers (secureAxiosRequest and secureFetch) intended to prevent Server-Side Request Forgery (SSRF) contain multiple logic fla...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 23.04.2026 19:15:14
  • Zuletzt bearbeitet 25.04.2026 02:16:02

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) protection bypass vulnerability exists in the Custom Function feature. While the application implements SSRF...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 23.04.2026 19:14:26
  • Zuletzt bearbeitet 24.04.2026 19:17:11

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload settings can be modified to allow the application/javascript MIME type. This lets an attacker upload .js f...

Exploit
  • EPSS 13.79%
  • Veröffentlicht 23.04.2026 19:13:36
  • Zuletzt bearbeitet 24.04.2026 15:14:39

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthenticated remote command execution (RCE) vulnerability. It can be exploited via a parameter override by...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 23.04.2026 19:12:26
  • Zuletzt bearbeitet 24.04.2026 15:14:48

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection) vulnerability in the account registration endpoint of Flowise Cloud allows unauthenticated attackers...