Skip to content

Flowise security advisories

112 advisories · 71 critical or high in 12 months · latest Aug 4

60 of 112 advisories

DateAdvisory
Aug 4Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens , enables token theft for any connected service
CVE-2026-70478Criticalfixed in 3.1.3
Aug 4Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
CVE-2026-70477Criticalfixed in 3.1.3
Aug 4Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
CVE-2026-70476Highfixed in 3.1.3
Aug 4Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
CVE-2026-73603Mediumfixed in 3.1.4
Aug 4Flowise: Missing Authorization on Execution Update Endpoint
CVE-2026-70475Highfixed in 3.1.3
Aug 4Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
CVE-2026-70474Highfixed in 3.1.3
Aug 4Flowise: Incomplete Credential Redaction Exposes Secrets via API
CVE-2026-73604Medium6.5fixed in 3.1.3
Aug 4Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
CVE-2026-70473Highfixed in 3.1.3
Aug 4Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
CVE-2026-70472Highfixed in 3.1.3
Aug 4Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
CVE-2026-69264Criticalfixed in 3.1.3
Aug 4Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
GHSA-88pr-878c-24wfHighfixed in 3.1.3
Aug 4Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
CVE-2026-70471Highfixed in 3.1.3
Aug 4Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
CVE-2026-70470Criticalfixed in 3.1.3
Aug 4Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
CVE-2026-69263Highfixed in 3.1.3
Aug 4Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
CVE-2026-69262Highfixed in 3.1.3
Aug 4Flowise RCE via SQLite Record Manager Node
CVE-2026-69259Criticalfixed in 3.1.3
Aug 4Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
CVE-2026-69258Highfixed in 3.1.3
Aug 4Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
CVE-2026-69257Highfixed in 3.1.3
Aug 4Flowise: Remote Code Execution Vulnerability in CSVAgent
CVE-2026-69256Criticalfixed in 3.1.3
Aug 4Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection , Root Shell Verified
CVE-2026-69255Criticalfixed in 3.1.3
Aug 4Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
CVE-2026-69254Criticalfixed in 3.1.3
Aug 4Flowise Sandbox Escape to RCE
CVE-2026-69253Criticalfixed in 3.1.3
Aug 4Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
CVE-2026-69252Highfixed in 3.1.3
Aug 4Flowise RCE via TypeORM DataSource
CVE-2026-69251Criticalfixed in 3.1.3
Aug 4Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
CVE-2026-69250Highfixed in 3.1.3
Aug 4Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
CVE-2026-73488Mediumfixed in 3.1.3
May 20Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows
CVE-2026-56268Medium7.7fixed in 3.1.2
May 20Flowise: Mass Assignment in PUT /api/v1/user Allows Authenticated Users to Override Password Hash and Bypass Password Change Verification
CVE-2026-56276Mediumfixed in 3.1.2
May 20Flowise: Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpage
CVE-2026-56277Mediumfixed in 3.1.2
May 14FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover
CVE-2026-46480High8.8fixed in 3.1.2
May 14FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover
CVE-2026-46479High8.8fixed in 3.1.2
May 14FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover
CVE-2026-46478High8.8fixed in 3.1.2
May 14FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover
CVE-2026-46477High8.8fixed in 3.1.2
May 14FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover
CVE-2026-46476Highfixed in 3.1.2
May 14FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover
CVE-2026-46475High8.8fixed in 3.1.2
May 14FlowiseAI: Vector Store No Permission Checks
CVE-2026-46444High8.8fixed in 3.1.2
May 14FlowiseAI Vulnerable to Credential Data Leak
CVE-2026-46443Highfixed in 3.1.2
May 14FlowiseAI: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
CVE-2026-46442Criticalfixed in 3.1.2
May 14FlowiseAI has Mass Assignment in Assistant Update Endpoint that Allows Cross-Workspace Resource Reassignment
CVE-2026-46441Highfixed in 3.1.2
May 14Flowise has an MCP Security Bypass that Enables RCE
CVE-2026-56274Highfixed in 3.1.2
May 14FlowiseAI Exposes Basic Auth Credentials via API
CVE-2026-46440High7.5fixed in 3.1.2
May 14FlowiseAI has Mass Assignment in Chatflow Update Endpoint that Allows Cross-Workspace AgentFlow Reassignment
CVE-2026-42863Highfixed in 3.1.2
May 14FlowiseAI has Mass Assignment in Tool Update Endpoint that Allows Cross-Workspace Resource Reassignment
CVE-2026-42862Highfixed in 3.1.2
May 14FlowiseAI has Mass Assignment in Variable Update Endpoint that Allows Cross-Workspace Resource Reassignment
CVE-2026-42861Highfixed in 3.1.2
May 6Flowise: Bcrypt Password Hash Exposure
CVE-2026-8026Medium3.7no fix yet
Apr 21Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
CVE-2026-41264Critical9.8fixed in 3.1.0
Apr 18Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
CVE-2026-41265Critical9.8fixed in 3.1.0
Apr 17Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs , enables API credit abuse via stored credentials
CVE-2026-41279High7.5fixed in 3.1.0
Apr 17Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs
CVE-2026-41278High7.5fixed in 3.1.0
Apr 17Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
CVE-2026-41277High8.8fixed in 3.1.0
Apr 16Flowise: resetPassword Authentication Bypass Vulnerability
CVE-2026-41276High9.8fixed in 3.1.0
Apr 16Flowise: Cypher Injection in GraphCypherQAChain
CVE-2026-41274Highfixed in 3.1.0
Apr 16Flowise: Password Reset Link Sent Over Unsecured HTTP
CVE-2026-41275High7.5fixed in 3.1.0
Apr 16Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow in Flowise
CVE-2026-41273High8.2fixed in 3.1.0
Apr 16Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains
CVE-2026-41271High7.1fixed in 3.1.0
Apr 16Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)
CVE-2026-41272High7.1fixed in 3.1.0
Apr 16Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
CVE-2026-41270High7.1fixed in 3.1.0
Apr 16Flowise: File Upload Validation Bypass in createAttachment
CVE-2026-41269High7.1fixed in 3.1.0
Apr 16Flowise: Parameter Override Bypass Remote Command Execution
CVE-2026-41268High7.7fixed in 3.1.0
Apr 16Flowise: Sensitive Data Leak in public-chatbotConfig
CVE-2026-41266High7.5fixed in 3.1.0
About Flowise

Build agents and LLM flows visually.

Packages watched: flowise (npm).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.