📦 Flowise

by Flowiseai

🔍 What is Flowise?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-34267

CRITICAL CVSS 9.9 Oct 14, 2025

Flowise versions 3.0.1 through 3.0.7 and all later versions with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability. An authenticated attacker can create or run t...

CVE-2025-61913

CRITICAL CVSS 9.9 Oct 8, 2025

This vulnerability in Flowise allows authenticated attackers to read and write arbitrary files anywhere on the file system due to insufficient path restrictions in WriteFileTool and ReadFileTool compo...

CVE-2025-59528

CRITICAL CVSS 10.0 Sep 22, 2025

Flowise versions 3.0.5 and below contain a critical remote code execution vulnerability in the CustomMCP node. Attackers can execute arbitrary JavaScript code with full Node.js privileges by manipulat...

CVE-2025-58434

CRITICAL CVSS 9.8 Sep 12, 2025

This vulnerability in Flowise allows unauthenticated attackers to generate password reset tokens for any user account, leading to complete account takeover. It affects both cloud-hosted and self-hoste...

CVE-2025-26319

CRITICAL CVSS 9.8 Mar 4, 2025

FlowiseAI Flowise v2.2.6 contains an arbitrary file upload vulnerability in the /api/v1/attachments endpoint that allows attackers to upload malicious files without proper validation. This affects all...

CVE-2024-8181

CRITICAL CVSS 9.8 Aug 27, 2024

An authentication bypass vulnerability in Flowise version 1.8.2 allows remote unauthenticated attackers to access administrator API endpoints and restricted functionality. This affects all deployments...

CVE-2025-61687

HIGH CVSS 8.3 Oct 6, 2025

FlowiseAI version 3.0.7 contains a file upload vulnerability that allows authenticated users to upload arbitrary files without validation. This enables attackers to store malicious Node.js web shells ...

CVE-2025-29192

HIGH CVSS 8.2 Oct 6, 2025

This Cross-Site Scripting (XSS) vulnerability in Flowise allows attackers to inject malicious scripts via FORM and INPUT elements in chat logs. When an admin views these logs, the scripts execute in t...

CVE-2025-59527

HIGH CVSS 7.5 Sep 22, 2025

This Server-Side Request Forgery (SSRF) vulnerability in Flowise version 3.0.5 allows attackers to use the application server as a proxy to access internal network services and explore their link stru...

CVE-2025-29189

HIGH CVSS 7.6 Apr 9, 2025

Flowise versions up to 2.2.3 contain a SQL injection vulnerability in the Postgres_VectorStores component via the tableName parameter. This allows attackers to execute arbitrary SQL commands on the da...

CVE-2024-36421

HIGH CVSS 7.5 Jul 1, 2024

Flowise version 1.4.3 has a CORS misconfiguration that allows arbitrary origins to connect to the website, potentially enabling cross-origin attacks. When combined with a path injection vulnerability,...

CVE-2024-31621

HIGH CVSS 7.6 Apr 29, 2024

This vulnerability allows remote attackers to execute arbitrary code on FlowiseAI installations by sending crafted scripts to the api/v1 component. It affects FlowiseAI Flowise versions 1.6.2 and earl...

CVE-2025-57164

MEDIUM CVSS 6.5 Oct 17, 2025

CVE-2025-57164 allows remote code execution in Flowise AI platforms through unsanitized user input in the Supabase RPC Filter field. Attackers can execute arbitrary code on vulnerable Flowise instance...

CVE-2024-37146

MEDIUM CVSS 6.1 Jul 1, 2024

Flowise version 1.4.3 has a reflected cross-site scripting vulnerability in the /api/v1/credentials/id endpoint that allows attackers to inject malicious JavaScript via crafted URLs. This can lead to ...

CVE-2024-36423

MEDIUM CVSS 6.1 Jul 1, 2024

Flowise version 1.4.3 has a reflected cross-site scripting vulnerability in the /api/v1/public-chatflows/id endpoint that allows attackers to inject malicious JavaScript via crafted URLs. This can lea...