Flowiseai

Flowise

125 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.27%
  • Veröffentlicht 28.06.2026 02:16:32
  • Zuletzt bearbeitet 06.07.2026 14:54:48

Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensitive, supplying 'node_options' bypasses the NODE_OPTIONS denylist entry...

Exploit
  • EPSS 0.86%
  • Veröffentlicht 25.06.2026 21:41:07
  • Zuletzt bearbeitet 01.07.2026 15:00:51

Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fileName parameters with ../ seq...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 25.06.2026 21:41:06
  • Zuletzt bearbeitet 01.07.2026 15:07:20

Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session token or a dev...

Exploit
  • EPSS 1.56%
  • Veröffentlicht 25.06.2026 21:41:06
  • Zuletzt bearbeitet 01.07.2026 15:02:24

Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands such as launching local MCP servers. Because Flowise's ...

Exploit
  • EPSS 3.9%
  • Veröffentlicht 25.06.2026 21:41:05
  • Zuletzt bearbeitet 01.07.2026 15:09:29

Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations. By supplying a path-trave...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 25.06.2026 21:41:04
  • Zuletzt bearbeitet 29.06.2026 18:46:58

Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section without supplying the current password or any additional verification,...

Exploit
  • EPSS 0.8%
  • Veröffentlicht 25.06.2026 21:41:04
  • Zuletzt bearbeitet 01.07.2026 15:10:52

Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicio...

Exploit
  • EPSS 0.58%
  • Veröffentlicht 25.06.2026 21:41:03
  • Zuletzt bearbeitet 29.06.2026 18:44:34

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint to register arbitrary accounts and ...

Exploit
  • EPSS 1.38%
  • Veröffentlicht 25.06.2026 21:41:02
  • Zuletzt bearbeitet 30.06.2026 05:17:31

Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints. The chatId value is not validated and is passed to streamStorageFile(), w...

  • EPSS 0.07%
  • Veröffentlicht 24.06.2026 11:53:15
  • Zuletzt bearbeitet 26.06.2026 02:01:32

Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password hashes approximately 30 times faster with modern GPU hardware, potential...