These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-12T12:16:45.290Z and has not been modified since then. Flowise before 3.1.0 uses weak hardcoded default JWT secrets and audience and issuer values in its enterprise passport authentication middleware. When environment variables are not set, the application falls back to these publicly known defaults [truncated]
CVE-2026-56273 is a path traversal vulnerability in Faiss and SimpleStore vector store implementations of Flowise before 3.1.0. Attackers with valid API tokens can write vector store data to arbitrary filesystem locations, potentially enabling code execution or data exfiltration. This vulnerability has a CVSS score of 4.9 and is considered Medium priority. Users of Flowise before version 3.1.0 should be a [truncated]
CVE-2025-71336 is a critical unsandboxed remote code execution vulnerability in Flowise, a platform that allows users to create and manage custom machine learning models. The vulnerability exists in the Custom MCP feature, which is designed to execute OS commands such as launching local MCP servers. Due to Flowise's minimal authentication and authorization model, which lacks role-based access control, an [truncated]
CVE-2025-71335 is a high-severity vulnerability in Flowise, a platform that fails to invalidate existing user sessions and session tokens after a password change. This oversight allows an attacker who has obtained a valid session token, for instance through a stolen session token or a device left logged in, to remain authenticated as the legitimate user even after the user has changed their password. The [truncated]
CVE-2025-71334 is a critical vulnerability in Flowise, a platform for building AI workflows. The vulnerability allows unauthenticated attackers to access and write arbitrary files due to missing validation of chatflowId and chatId parameters. This can lead to remote code execution. The vulnerability affects Flowise versions 2.2.8 and earlier, prior to 3.0.6. The CVSS score for this vulnerability is 9.3, i [truncated]
CVE-2025-71333 is a critical vulnerability in Flowise, a platform for building AI workflows. The vulnerability allows unauthenticated attackers to upload files through the /api/v1/attachments endpoint when storageType is set to local. By exploiting path traversal in the chatId and chatflowId parameters, attackers can upload malicious files to arbitrary directories, potentially enabling remote code executi [truncated]
CVE-2025-71328 is an unverified password change vulnerability in Flowise, a product by FlowiseAI, before version 3.0.10. An authenticated user can change their account password through the account settings (Security) section without supplying the current password or any additional verification. The application does not enforce a current-password check on the credential change, which can lead to full accou [truncated]
CVE-2025-71327 is a critical authentication bypass vulnerability in Flowise, a software developed by FlowiseAI. The vulnerability exists in the unprotected /api/v1/account/register endpoint, which allows unauthenticated attackers to create arbitrary user accounts and gain full API access without credentials. This vulnerability has a CVSS score of 9.3 and is classified as CRITICAL. The CVE record was publi [truncated]
CVE-2025-71337 is a HIGH-severity vulnerability in Flowise, a product by Flowiseai, affecting versions 3.0.7 and earlier. An authenticated user can change the account email address via the account profile endpoint without confirming the change to the original email address or re-entering the current password. This allows an attacker to take over the account and abuse password reset mechanisms. The vulnera [truncated]
CVE-2026-56268 is an information disclosure vulnerability in Flowise, a platform used for building chatflows. The vulnerability exists in the /api/v1/chatflows/apikey/:apikey endpoint. When the keyonly query parameter is omitted, which is the default behavior, the endpoint returns not only the chatflows bound to the supplied API key but also all chatflows across every workspace that have no API key assign [truncated]
CVE-2026-56276 is a medium-severity vulnerability in Flowise, a platform that allows users to create and manage AI workflows. The vulnerability exists in the PUT /api/v1/user endpoint and enables authenticated users to modify the credential field without validation, potentially allowing attackers to bypass password change verification and session invalidation. This could lead to persistent account access [truncated]
CVE-2024-58351 is a critical vulnerability in Flowise, a platform that allows configuration to be injected into the Chainflow during execution via the overrideConfig option. This feature, enabled by default with no allow-list of permitted variables, relies on vm2 for sandboxing. An attacker can exploit this to achieve remote code execution, denial of service, server-side request forgery, prompt injection, [truncated]