CVE-2026-46479
- EPSS 0.34%
- Veröffentlicht 08.06.2026 15:32:03
- Zuletzt bearbeitet 23.07.2026 07:10:00
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment allows cross-workspace evaluation takeover. This issue has been patched in version 3.1.2.
CVE-2026-46478
- EPSS 0.34%
- Veröffentlicht 08.06.2026 15:31:55
- Zuletzt bearbeitet 23.07.2026 07:10:00
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, DatasetRow create and update mass-assignment allows cross-workspace row takeover. This issue has been patched in version 3.1.2.
CVE-2026-46477
- EPSS 0.34%
- Veröffentlicht 08.06.2026 15:31:48
- Zuletzt bearbeitet 23.07.2026 07:10:00
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, dataset create and update mass-assignment allows cross-workspace dataset takeover. This issue has been patched in version 3.1.2.
CVE-2026-46476
- EPSS 0.34%
- Veröffentlicht 08.06.2026 15:31:32
- Zuletzt bearbeitet 23.07.2026 07:10:00
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomTemplate create and update mass-assignment allows cross-workspace template takeover. This issue has been patched in version 3.1.2.
CVE-2026-46475
- EPSS 0.34%
- Veröffentlicht 08.06.2026 15:31:09
- Zuletzt bearbeitet 23.07.2026 07:10:00
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, assistant create and update mass-assignment allows cross-workspace assistant takeover. This issue has been patched in version 3.1.2.
CVE-2026-46443
- EPSS 0.27%
- Veröffentlicht 08.06.2026 15:30:59
- Zuletzt bearbeitet 23.07.2026 07:10:00
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with a credentialName filter parameter, the encryptedData field is not stripped from the response. The code ...
CVE-2026-46442
- EPSS 3.49%
- Veröffentlicht 08.06.2026 15:30:48
- Zuletzt bearbeitet 23.07.2026 07:10:00
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScr...
CVE-2026-46441
- EPSS 0.27%
- Veröffentlicht 08.06.2026 15:30:36
- Zuletzt bearbeitet 23.07.2026 07:10:00
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. The endpoint allows authenticated users to modify s...
CVE-2026-46440
- EPSS 0.25%
- Veröffentlicht 08.06.2026 15:29:40
- Zuletzt bearbeitet 23.07.2026 07:10:00
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison. This issue has been patc...
CVE-2026-42863
- EPSS 0.27%
- Veröffentlicht 08.06.2026 15:29:24
- Zuletzt bearbeitet 23.07.2026 07:10:00
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the chatflow update endpoint of FlowiseAI. The endpoint allows clients to modify server-control...