| A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file… CVE-2026-90580 | Severity medium |
| Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that… CVE-2026-90535 | Severity high |
| Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST… CVE-2026-90534 | Severity medium |
| Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated… CVE-2026-90533 | Severity medium |
| Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential… CVE-2026-70636 | Severity high |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST… CVE-2026-70478 | Severity critical |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a… CVE-2026-70477 | Severity critical |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing… CVE-2026-70476 | Severity high |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id… CVE-2026-70475 | Severity medium |
| Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three… CVE-2026-70474 | Severity high |
| Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET… CVE-2026-70473 | Severity high |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise… CVE-2026-70472 | Severity high |
| Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars… CVE-2026-70471 | Severity medium |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise… CVE-2026-70470 | Severity critical |
| Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code… CVE-2026-69264 | Severity critical |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943… CVE-2026-69263 | Severity critical |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id`… CVE-2026-69262 | Severity high |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in… CVE-2026-69259 | Severity high |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST… CVE-2026-69258 | Severity critical |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module… CVE-2026-69257 | Severity high |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to… CVE-2026-69256 | Severity high |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in… CVE-2026-69255 | Severity high |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted… CVE-2026-69254 | Severity high |
| Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several… CVE-2026-69253 | Severity high |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was… CVE-2026-69252 | Severity high |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent… CVE-2026-69251 | Severity high |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint… CVE-2026-69250 | Severity high |
| Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows… CVE-2026-67622 | Severity critical |
| Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized… CVE-2026-67621 | Severity high |
| An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint CVE-2026-52098 | Severity critical |
| Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write… CVE-2025-71338 | Severity critical |
| Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authenticated user can… CVE-2025-71337 | Severity high |
| Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the… CVE-2025-71336 | Severity critical |
| Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes… CVE-2025-71335 | Severity high |
| Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that… CVE-2025-71334 | Severity critical |
| Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType… CVE-2025-71333 | Severity critical |
| Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation of the chatflow.id… CVE-2025-71332 | Severity high |
| Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through… CVE-2025-71328 | Severity high |
| Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated… CVE-2025-71327 | Severity critical |
| Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and… CVE-2025-71324 | Severity high |
| Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and… CVE-2025-61913 | Severity critical |
| Flowise is a drag & drop user interface to build a customized large language model flow. A file upload vulnerability in version 3.0.7 of… CVE-2025-61687 | Severity high |
| Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, a Server-Side Request Forgery… CVE-2025-59527 | Severity high |
| Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the… CVE-2025-58434 | Severity critical |
| Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log. CVE-2025-50538 | Severity medium |
| Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability… CVE-2025-34267 | Severity critical |
| Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log. CVE-2025-29192 | Severity medium |
| Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores. CVE-2025-29189 | Severity high |
| FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments. CVE-2025-26319 | Severity critical |