VulnSea

FlowiseAI has 46 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 45 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 29. The median CVSS is 8.5 (high), with 11 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-862 (9) and CWE-94 (8).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.5
Publish → KEV
Last 90 days
45 prev 0

Products

  • Flowise 46
46
Total CVEs
11
Critical
0
CISA KEV
0
Exploited

FlowiseAI vulnerabilities

CVEs affecting FlowiseAI, newest first. Open any entry for full detail, references, and exploit status.

46 CVEsRSS

CVE-2026-91930High· 7.5PoC
1w ago

Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs

Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, cre…

MidnightFlowiseAI · FlowiseEPSS 0.37%via NVD
CVE-2026-91932High· 8.5PoC
1w ago

Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter

Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean fil…

MidnightFlowiseAI · FlowiseEPSS 0.82%via NVD
CVE-2026-91929High· 7.1
1w ago

Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations

Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves i…

TwilightFlowiseAI · FlowiseEPSS 0.33%via NVD
CVE-2026-91937High· 7.5
1w ago

Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node

Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to r…

TwilightFlowiseAI · FlowiseEPSS 0.28%via NVD
CVE-2026-91936Medium· 6.8PoC
1w ago

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shel…

TwilightFlowiseAI · FlowiseEPSS 0.35%via NVD
CVE-2026-91934High· 8.8
1w ago

Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files

Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to sy…

TwilightFlowiseAI · FlowiseEPSS 0.69%via NVD
CVE-2026-91933High· 7.1
1w ago

Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid

Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can i…

TwilightFlowiseAI · FlowiseEPSS 0.33%via NVD
CVE-2026-91931High· 8.5PoC
1w ago

Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter

Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invok…

MidnightFlowiseAI · FlowiseEPSS 0.63%via NVD
CVE-2026-91938High· 7.1
1w ago

Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection

Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, inte…

TwilightFlowiseAI · FlowiseEPSS 0.35%via NVD
CVE-2026-91935High· 8.3PoC
1w ago

Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts

Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provi…

MidnightFlowiseAI · FlowiseEPSS 0.27%via NVD
CVE-2026-90580Medium· 6.3PoC
1w ago

A vulnerability was found in FlowiseAI Flowise up to 3.0.2

A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of th…

Twilightflowiseai · flowiseEPSS 0.23%via NVD
CVE-2026-90535High· 7.5PoC
1w ago

Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification

Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminat…

Midnightflowiseai · flowiseEPSS 0.27%via NVD
CVE-2026-90534Medium· 6.5
1w ago

Flowise is a low-code platform for building LLM applications

Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission check and invokes component loadMethods w…

Sunlitflowiseai · flowiseEPSS 0.21%via NVD
CVE-2026-90533Medium· 6.5PoC
1w ago

Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user record including bcrypt password hash an…

Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user record including bcrypt password hash an…

Twilightflowiseai · flowiseEPSS 0.19%via NVD
CVE-2026-52098Critical· 9.8
1w ago

An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint

An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint

Midnightflowiseai · flowiseEPSS 0.78%via NVD
CVE-2026-73604Medium· 6.5
1mo ago

Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext

Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sen…

Sunlitflowiseai · flowiseEPSS 0.36%via NVD
CVE-2026-73603Medium· 5.3
1mo ago

Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials

Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audi…

Sunlitflowiseai · flowiseEPSS 0.34%via NVD
CVE-2026-73602Critical· 9.9
1mo ago

Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass

Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object …

Midnightflowiseai · flowiseEPSS 0.84%via NVD
CVE-2026-73601High· 8.8
1mo ago

Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables…

Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables…

Twilightflowiseai · flowiseEPSS 0.88%via NVD
CVE-2026-67622Critical· 9.9
1mo ago

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary crede…

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary crede…

Midnightflowiseai · flowiseEPSS 0.32%via NVD
CVE-2026-67621High· 7.6
1mo ago

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-l…

Twilightflowiseai · flowiseEPSS 0.34%via NVD
CVE-2026-70636High· 7.5
1mo ago

Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware d…

Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware d…

Twilightflowiseai · flowiseEPSS 0.49%via NVD
CVE-2026-70475Medium· 6.5
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lacks the checkAnyPermission() middleware …

Sunlitflowiseai · flowiseEPSS 0.31%via NVD
CVE-2026-70476High· 8.2
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterp…

Twilightflowiseai · flowiseEPSS 0.32%via NVD
CVE-2026-70477Critical· 9.8
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypass…

Midnightflowiseai · flowiseEPSS 0.83%via NVD
CVE-2026-70478Critical· 10.0
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The …

Midnightflowiseai · flowiseEPSS 0.53%via NVD
CVE-2026-70471Medium· 6.5
1mo ago

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protecte…

Sunlitflowiseai · flowiseEPSS 0.25%via NVD
CVE-2026-69264Critical· 9.8
1mo ago

Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide

Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to gl…

Midnightflowiseai · flowiseEPSS 1.2%via NVD
CVE-2026-70472High· 8.8
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without …

Twilightflowiseai · flowiseEPSS 0.34%via NVD
CVE-2026-70473High· 8.5
1mo ago

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requestin…

Twilightflowiseai · flowiseEPSS 0.29%via NVD
FlowiseAI vulnerabilities (CVEs) · VulnSea