CVE-2026-90580FlowiseAI Flowise Evaluations Endpoint index.ts axios.post server-side request forgery Exploitation status Public exploit Fix YesAffected product F Flowise Published 09/13/2026 Severity Medium CVE-2026-90535Flowise before 3.1.4 Denial of Service via text-to-speech/abort Exploitation status Public exploit Fix YesAffected product F Flowise Published 09/12/2026 Severity Medium CVE-2026-90534Flowise before 3.1.4 Cross-Workspace Credential IDOR via node-load-method Exploitation status Not known exploited Fix YesAffected product F Flowise Published 09/12/2026 Severity Medium CVE-2026-90533Flowise before 3.1.4 Broken Access Control via organizationuser Exploitation status Public exploit Fix YesAffected product F Flowise Published 09/12/2026 Severity Medium CVE-2026-73604Flowise before 3.1.3 Credential Exposure via API Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/13/2026 Severity High CVE-2026-73603Flowise before 3.1.4 Credential Abuse via Text-to-Speech Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/13/2026 Severity Medium CVE-2026-73602Flowise before 3.1.3 Sandbox Escape to RCE Exploitation status Not known exploited Fix YesAffected product F Flowise Published 08/13/2026 Severity Critical CVE-2026-73601Flowise before 3.1.3 Remote Code Execution via Custom MCP Exploitation status Not known exploited Fix YesAffected product F Flowise Published 08/13/2026 Severity Critical CVE-2026-73488Flowise before 3.1.3 IDOR via customer-default-source endpoint Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/13/2026 Severity Medium CVE-2026-73487Flowise before 3.1.3 Prompt Injection RCE via CSV Agent Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/13/2026 Severity Critical CVE-2026-73486Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/13/2026 Severity Critical CVE-2026-73485Flowise before 3.1.3 Remote Code Execution via Airtable Agent Exploitation status Not known exploited Fix YesAffected product F Flowise Published 08/13/2026 Severity Critical CVE-2026-73484Flowise before 3.1.3 Sandbox Escape via Pandas Methods Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/13/2026 Severity High CVE-2026-73483Flowise before 3.1.3 Sandbox Escape via Puppeteer Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/13/2026 Severity Critical CVE-2026-71962Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download Exploitation status Public exploit Fix Not confirmed Affected product F Flowise Published 08/10/2026 Severity High CVE-2026-67620Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List Exploitation status Public exploit Fix Not confirmed Affected product F Flowise Published 08/08/2026 Severity Medium CVE-2026-70636Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint Exploitation status Public exploit Fix Not confirmed Affected product F Flowise Published 08/06/2026 Severity High CVE-2026-67622Flowise 3.1.4 IDOR in OpenAI Assistants Integration Exploitation status Public exploit Fix Not confirmed Affected product F Flowise Published 08/06/2026 Severity High CVE-2026-67621Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints Exploitation status Public exploit Fix Not confirmed Affected product F Flowise Published 08/06/2026 Severity High CVE-2026-70478Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity Critical CVE-2026-70477Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity Critical CVE-2026-70476Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity High CVE-2026-70475Flowise: Missing Authorization on Execution Update Endpoint Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity High CVE-2026-70474Flowise: Cross-Workspace OAuth2 Credential Metadata Leak Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity High CVE-2026-70473Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity High CVE-2026-70472Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity High CVE-2026-70471Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure Exploitation status Not known exploited Fix YesAffected product F Flowise Published 08/04/2026 Severity High CVE-2026-70470Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity Critical CVE-2026-69264Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity Critical CVE-2026-69263Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE) Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity High CVE-2026-69262Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity High CVE-2026-69259Flowise RCE via SQLite Record Manager Node Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity Critical CVE-2026-69258Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity High CVE-2026-69257Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity High CVE-2026-69256Flowise: Remote Code Execution Vulnerability in CSVAgent Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity Critical CVE-2026-69255Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity Critical CVE-2026-69254Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity Critical CVE-2026-69253Flowise Sandbox Escape to RCE Exploitation status Not known exploited Fix YesAffected product F Flowise Published 08/04/2026 Severity Critical CVE-2026-69252Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity High CVE-2026-69251Flowise RCE via TypeORM DataSource Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity Critical CVE-2026-69250Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration Exploitation status Public exploit Fix YesAffected product F Flowise Published 08/04/2026 Severity High CVE-2026-56271Flowise - Weak Default JWT Secrets in Authentication Middleware Exploitation status Not known exploited Fix YesAffected product F Flowise Published 07/12/2026 Severity Critical CVE-2026-56278Flowise - Session Hijacking via Weak Default Express Session Secret Exploitation status Not known exploited Fix YesAffected product F Flowise Published 06/30/2026 Severity Critical CVE-2026-56277Flowise - Hardcoded CORS Wildcard in TTS Endpoint Exploitation status Not known exploited Fix YesAffected product F Flowise Published 06/30/2026 Severity Medium CVE-2026-58057Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/28/2026 Severity Low CVE-2025-71338Flowise - Arbitrary File Write to Remote Code Execution via document-store API Exploitation status Public exploit Fix Not confirmed Affected product F Flowise Published 06/25/2026 Severity Critical CVE-2025-71336Flowise - Unsandboxed Remote Code Execution via Custom MCP Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/25/2026 Severity Critical CVE-2025-71335Flowise - Session Invalidation Failure After Password Change Exploitation status Not known exploited Fix YesAffected product F Flowise Published 06/25/2026 Severity High CVE-2025-71334Flowise - Arbitrary File Access via Missing Chat Flow ID Validation Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/25/2026 Severity Critical CVE-2025-71333Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/25/2026 Severity Critical CVE-2025-71328Flowise - Unverified Password Change via Account Settings Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/25/2026 Severity High CVE-2025-71327Flowise - Authentication Bypass via Unprotected Registration Endpoint Exploitation status Public exploit Fix Not confirmed Affected product F Flowise Published 06/25/2026 Severity Critical CVE-2025-71324Flowise - Arbitrary File Read via chatId Parameter Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/25/2026 Severity High CVE-2026-56272Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing Exploitation status Not known exploited Fix YesAffected product F Flowise Published 06/24/2026 Severity Medium CVE-2026-56270Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/24/2026 Severity High CVE-2026-56269Flowise - Weak Default Token Hash Secret in JWT Token Encryption Exploitation status Not known exploited Fix YesAffected product F Flowise Published 06/24/2026 Severity Medium CVE-2025-71332Flowise - SQL Injection in importChatflows API via chatflow.id Parameter Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/24/2026 Severity High CVE-2026-56275Flowise - Server-Side Request Forgery via Execute Flow Base URL Exploitation status Not known exploited Fix YesAffected product F Flowise Published 06/23/2026 Severity Medium CVE-2026-56274Flowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/23/2026 Severity High CVE-2025-71337Flowise - Unverified Email Change via Account Profile Endpoint Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/23/2026 Severity High CVE-2026-56268Flowise - Cross-Workspace Information Disclosure via chatflows/apikey Endpoint Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/22/2026 Severity Medium CVE-2026-12821FlowiseAI Flowise S3 Document Loader S3.ts path traversal Exploitation status Public exploit Fix Not confirmed Affected product F Flowise Published 06/21/2026 Severity Medium CVE-2025-71331Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/20/2026 Severity Medium CVE-2026-46480Flowise: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/08/2026 Severity High CVE-2026-46479Flowise: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/08/2026 Severity High CVE-2026-46478Flowise: DatasetRow create+update mass-assignment allows cross-workspace row takeover Exploitation status Not known exploited Fix YesAffected product F Flowise Published 06/08/2026 Severity High CVE-2026-46477Flowise: Dataset create+update mass-assignment allows cross-workspace dataset takeover Exploitation status Not known exploited Fix YesAffected product F Flowise Published 06/08/2026 Severity High CVE-2026-46476Flowise: CustomTemplate create+update mass-assignment allows cross-workspace template takeover Exploitation status Not known exploited Fix YesAffected product F Flowise Published 06/08/2026 Severity High CVE-2026-46475Flowise: Assistant create+update mass-assignment allows cross-workspace assistant takeover Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/08/2026 Severity High CVE-2026-46443Flowise: Credential Data Leak Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/08/2026 Severity High CVE-2026-46442Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/08/2026 Severity Critical CVE-2026-46441Flowise: Mass Assignment in Assistant Update Endpoint Allows Cross-Workspace Resource Reassignment Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/08/2026 Severity High CVE-2026-46440Flowise: Basic Auth Credentials Exposed via API Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/08/2026 Severity High CVE-2026-42863Flowise: Mass Assignment in Chatflow Update Endpoint Allows Cross-Workspace AgentFlow Reassignment Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/08/2026 Severity High CVE-2026-42862Flowise: Mass Assignment in Tool Update Endpoint Allows Cross-Workspace Resource Reassignment Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/08/2026 Severity High CVE-2026-42861Flowise: Mass Assignment in Variable Update Endpoint Allows Cross-Workspace Resource Reassignment Exploitation status Public exploit Fix YesAffected product F Flowise Published 06/08/2026 Severity High CVE-2026-46444Flowise: Vector Store No Permission Checks Exploitation status Not known exploited Fix YesAffected product F Flowise Published 06/08/2026 Severity High CVE-2026-43995Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure) Exploitation status Public exploit Fix YesAffected product F Flowise Published 05/11/2026 Severity Medium CVE-2026-8028FlowiseAI Flowise Endpoint account.service.ts verify information disclosure Exploitation status Public exploit Fix Not confirmed Affected product F Flowise Published 05/06/2026 Severity Medium CVE-2026-8027FlowiseAI Flowise User Controller authorization Exploitation status Public exploit Fix Not confirmed Affected product F Flowise Published 05/06/2026 Severity Medium CVE-2026-8026FlowiseAI Flowise API Response account.service.ts login information disclosure Exploitation status Public exploit Fix Not confirmed Affected product F Flowise Published 05/06/2026 Severity Medium CVE-2026-41274Flowise: Cypher Injection in GraphCypherQAChain Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/23/2026 Severity Critical CVE-2026-41264Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/23/2026 Severity Critical CVE-2026-41265Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/23/2026 Severity Critical CVE-2026-41279Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials Exploitation status Not known exploited Fix YesAffected product F Flowise Published 04/23/2026 Severity High CVE-2026-41278Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs Exploitation status Not known exploited Fix YesAffected product F Flowise Published 04/23/2026 Severity High CVE-2026-41276Flowise: AccountService resetPassword Authentication Bypass Vulnerability Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/23/2026 Severity High CVE-2026-41277Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR) Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/23/2026 Severity High CVE-2026-41275Flowise: Password Reset Link Sent Over Unsecured HTTP Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/23/2026 Severity High CVE-2026-41273Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/23/2026 Severity High CVE-2026-41271Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/23/2026 Severity High CVE-2026-41272Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure) Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/23/2026 Severity High CVE-2026-41270Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/23/2026 Severity High CVE-2026-41269Flowise: File Upload Validation Bypass in createAttachment Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/23/2026 Severity High CVE-2026-41268Flowise: Flowise Parameter Override Bypass Remote Command Execution Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/23/2026 Severity High CVE-2026-41267Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/23/2026 Severity High CVE-2026-41266Flowise: Sensitive Data Leak in public-chatbotConfig Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/23/2026 Severity High CVE-2026-41137Flowise: Code Injection in CSVAgent leads to Authenticated RCE Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/23/2026 Severity Critical CVE-2026-41138Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas. Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/23/2026 Severity High CVE-2026-40933Flowise: Authenticated RCE Via MCP Adapters Exploitation status Public exploit Fix YesAffected product F Flowise Published 04/21/2026 Severity Critical