Flowiseai
64 known vulnerabilities
Top Products
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refr
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the exp
Flowise before 3.1.2 sets Access-Control-Allow-Origin to a hardcoded wildcard (*) on its text-to-speech (TTS) generation
Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparis
Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauth
Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnera
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens aft
Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missin
Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoin
Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their accou
Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows
Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-fil
Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recom
Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginm
Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' fo
Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation
Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers
Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to inco
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authen
Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endpoint.
Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluat
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluat
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, Dataset
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, dataset
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomT
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, assista
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRU
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when cr
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /a
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the che
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool i
A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/se
A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functiona
A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packag
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypher
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-spe
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignme
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerabil
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password re
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contain
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core securi
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side R
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side R
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow co
Frequently Asked Questions
How many CVEs affect Flowiseai?
Flowiseai has 64 CVE records in our database, including 21 critical and 32 high severity vulnerabilities.
What are the most severe Flowiseai vulnerabilities?
Flowiseai has 21 critical severity (CVSS 9.0+) and 32 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Flowiseai vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Flowiseai products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Flowiseai Vulnerabilities
CyberStrike scans your infrastructure for Flowiseai vulnerabilities and provides real-time remediation guidance.
Get Started