flowiseai
AI / MLoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting flowiseai.
- CVE-2026-73604Flowise before 3.1.3 Credential Exposure via API6.5
- CVE-2026-71962Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download7.5
- CVE-2026-67620Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List7.7
- CVE-2026-70636Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint7.5
- CVE-2026-67622Flowise 3.1.4 IDOR in OpenAI Assistants Integration9.9
- CVE-2026-67621Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints7.6
- CVE-2026-56271Flowise - Weak Default JWT Secrets in Authentication Middleware9.8
- CVE-2026-56277Flowise - Hardcoded CORS Wildcard in TTS Endpoint6.5
- CVE-2026-56278Flowise - Session Hijacking via Weak Default Express Session Secret9.1
- CVE-2026-58057Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity5.0
- CVE-2025-71338Flowise - Arbitrary File Write to Remote Code Execution via document-store API10.0
- CVE-2025-71336Flowise - Unsandboxed Remote Code Execution via Custom MCP9.8
- CVE-2025-71335Flowise - Session Invalidation Failure After Password Change8.1
- CVE-2025-71334Flowise - Arbitrary File Access via Missing Chat Flow ID Validation9.8
- CVE-2025-71328Flowise - Unverified Password Change via Account Settings8.3