CVE-2026-41279
- EPSS 0.26%
- Veröffentlicht 23.04.2026 19:53:15
- Zuletzt bearbeitet 24.04.2026 16:31:36
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-speech generation endpoint (POST /api/v1/text-to-speech/generate) is whitelisted (no auth) and accepts a credentialId directly in the...
CVE-2026-41278
- EPSS 0.42%
- Veröffentlicht 23.04.2026 19:52:20
- Zuletzt bearbeitet 24.04.2026 16:31:51
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1/public-chatflows/:id endpoint returns the full chatflow object without sanitization for public chatflows. Docker validation revea...
CVE-2026-41276
- EPSS 6.87%
- Veröffentlicht 23.04.2026 19:49:26
- Zuletzt bearbeitet 24.04.2026 19:17:11
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass authentication on affected installations of FlowiseAI Flowise. Authentication is not require...
CVE-2026-41277
- EPSS 3.11%
- Veröffentlicht 23.04.2026 19:48:57
- Zuletzt bearbeitet 25.04.2026 02:16:02
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated users to control the primary key (id) and internal st...
CVE-2026-41275
- EPSS 0.19%
- Veröffentlicht 23.04.2026 19:33:44
- Zuletzt bearbeitet 25.04.2026 02:16:02
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on cloud.flowiseai.com sends a reset password link over the unsecured HTTP protocol instead of HTTPS. This behav...
CVE-2026-41273
- EPSS 0.31%
- Veröffentlicht 23.04.2026 19:29:16
- Zuletzt bearbeitet 24.04.2026 19:17:11
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass vulnerability that allows an unauthenticated attacker to obtain OAuth 2.0 access tokens associated with...
CVE-2026-41271
- EPSS 0.23%
- Veröffentlicht 23.04.2026 19:17:40
- Zuletzt bearbeitet 24.04.2026 16:37:54
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) vulnerability exists in FlowiseAI's POST/GET API Chain components that allows unauthenticated attackers to f...
CVE-2026-41272
- EPSS 0.26%
- Veröffentlicht 23.04.2026 19:16:08
- Zuletzt bearbeitet 24.04.2026 16:37:31
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core security wrappers (secureAxiosRequest and secureFetch) intended to prevent Server-Side Request Forgery (SSRF) contain multiple logic fla...
CVE-2026-41270
- EPSS 0.23%
- Veröffentlicht 23.04.2026 19:15:14
- Zuletzt bearbeitet 25.04.2026 02:16:02
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) protection bypass vulnerability exists in the Custom Function feature. While the application implements SSRF...
CVE-2026-41269
- EPSS 0.47%
- Veröffentlicht 23.04.2026 19:14:26
- Zuletzt bearbeitet 24.04.2026 19:17:11
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload settings can be modified to allow the application/javascript MIME type. This lets an attacker upload .js f...