Flowise-components
This hub aggregates every CVE we track for Flowise-components, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
OSS Librariesother
9
CVEs tracked
3
Critical
6
High
0
In CISA KEV
Severity distribution
HIGH6CRITICAL3
Monthly trend
0
0
0
0
0
0
0
1
0
0
0
0
0
1
0
0
0
0
1
6
0
0
0
0
2024-092026-08
Latest CVEs
The 9 most recently published vulnerabilities affecting Flowise-components.
- CVE-2026-41274Flowise: Cypher Injection in GraphCypherQAChain9.8
- CVE-2026-41271Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains8.3
- CVE-2026-41272Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)7.1
- CVE-2026-41270Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox7.1
- CVE-2026-41137Flowise: Code Injection in CSVAgent leads to Authenticated RCE8.8
- CVE-2026-40933Flowise: Authenticated RCE Via MCP Adapters9.9
- CVE-2026-31829Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access7.1
- CVE-2025-61913Flowise is vulnerable to arbitrary file read, arbitrary file write9.9
- CVE-2025-29189Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores.7.6
Product normalization is registry-driven with AI assist and human review. How it works