Flowiseai

Flowise

146 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 30.06.2026 22:08:27
  • Zuletzt bearbeitet 06.07.2026 15:27:21

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set (packages/server/src/enterprise/middleware...

Exploit
  • EPSS 1.27%
  • Veröffentlicht 28.06.2026 02:16:32
  • Zuletzt bearbeitet 06.07.2026 14:54:48

Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensitive, supplying 'node_options' bypasses the NODE_OPTIONS denylist entry...

Exploit
  • EPSS 0.86%
  • Veröffentlicht 25.06.2026 21:41:07
  • Zuletzt bearbeitet 30.09.2026 16:10:00

Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 25.06.2026 21:41:06
  • Zuletzt bearbeitet 30.09.2026 16:10:00

Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session token or a dev...

Exploit
  • EPSS 1.56%
  • Veröffentlicht 25.06.2026 21:41:06
  • Zuletzt bearbeitet 30.09.2026 16:10:00

Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands such as launching local MCP servers. Because Flowise's ...

Exploit
  • EPSS 3.9%
  • Veröffentlicht 25.06.2026 21:41:05
  • Zuletzt bearbeitet 30.09.2026 16:10:00

Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations. By supplying a path-trave...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 25.06.2026 21:41:04
  • Zuletzt bearbeitet 30.09.2026 16:10:00

Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section without supplying the current password or any additional verification,...

Exploit
  • EPSS 0.8%
  • Veröffentlicht 25.06.2026 21:41:04
  • Zuletzt bearbeitet 30.09.2026 16:10:00

Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicio...

Exploit
  • EPSS 0.58%
  • Veröffentlicht 25.06.2026 21:41:03
  • Zuletzt bearbeitet 30.09.2026 16:10:00

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint to register arbitrary accounts and ...

Exploit
  • EPSS 1.38%
  • Veröffentlicht 25.06.2026 21:41:02
  • Zuletzt bearbeitet 30.09.2026 16:10:00

Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints. The chatId value is not validated and is passed to streamStorageFile(), w...