CVE-2026-41266
- EPSS 0.35%
- Veröffentlicht 23.04.2026 19:11:32
- Zuletzt bearbeitet 25.04.2026 02:16:02
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes sensitive data including API keys, HTTP authorization headers and internal configuration without any ...
CVE-2026-41137
- EPSS 1.45%
- Veröffentlicht 23.04.2026 19:10:37
- Zuletzt bearbeitet 24.04.2026 15:15:47
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent allows providing a custom Pandas CSV read code. Due to lack of sanitization, an attacker can provide a command injection payload tha...
CVE-2026-41138
- EPSS 0.6%
- Veröffentlicht 23.04.2026 19:05:22
- Zuletzt bearbeitet 24.04.2026 19:17:11
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas. The user’s input is di...
CVE-2026-40933
- EPSS 1.99%
- Veröffentlicht 21.04.2026 21:00:35
- Zuletzt bearbeitet 23.04.2026 15:40:22
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command...
CVE-2026-31829
- EPSS 2.3%
- Veröffentlicht 10.03.2026 21:43:58
- Zuletzt bearbeitet 11.03.2026 14:24:01
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise exposes an HTTP Node in AgentFlow and Chatflow that performs server-side HTTP requests using user-controlled URLs. By default, there are...
CVE-2026-30822
- EPSS 12.9%
- Veröffentlicht 07.03.2026 05:16:27
- Zuletzt bearbeitet 11.03.2026 13:40:13
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauthenticated users can inject arbitrary values into internal database fields when creating leads. This issue has been patched in vers...
CVE-2026-30820
- EPSS 0.48%
- Veröffentlicht 07.03.2026 05:16:26
- Zuletzt bearbeitet 11.03.2026 13:46:22
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowise trusts any HTTP client that sets the header x-request-from: internal, allowing an authenticated tenant session to bypass all /ap...
CVE-2026-30821
- EPSS 18.33%
- Veröffentlicht 07.03.2026 05:16:26
- Zuletzt bearbeitet 11.03.2026 13:45:38
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId/:chatId endpoint is listed in WHITELIST_URLS, allowing unauthenticated access to the file upload API...
CVE-2026-30824
- EPSS 36.25%
- Veröffentlicht 07.03.2026 05:11:15
- Zuletzt bearbeitet 11.03.2026 13:35:41
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvidia-nim/*) is whitelisted in the global authentication middleware, allowing unauthenticated access to ...
CVE-2026-30823
- EPSS 0.45%
- Veröffentlicht 07.03.2026 05:10:08
- Zuletzt bearbeitet 11.03.2026 13:36:25
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue has been pat...