PatchSiren

FlowiseAI CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM FlowiseAI CVE published 2026-08-08

CVE-2026-67620

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts. The DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200. This allows authenticated attackers to force the server to issue arbitrary GET requests to cloud instance metadata services, potentially [truncated]

HIGH FlowiseAI CVE published 2026-08-06

CVE-2026-67622

AI-assisted PatchSiren debrief based on the supplied source corpus. CVE-2026-67622 is an insecure direct object reference vulnerability in Flowise's OpenAI Assistants integration, allowing authenticated attackers to access credentials for other workspaces. This can lead to enumeration of cross-workspace assistant metadata, retrieval of file and vector store listings, and upload of files into victim worksp [truncated]

HIGH FlowiseAI CVE published 2026-08-06

CVE-2026-67621

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:18:22.717Z and has not been modified since then. CVE-2026-67621 is a missing authorization vulnerability in Flowise through version 3.1.4. The vulnerability allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Att [truncated]

CRITICAL FlowiseAI CVE published 2026-08-04

CVE-2026-70478

The Flowise application, a drag & drop user interface for building customized large language model flows, contains a critical vulnerability in its OAuth2 credential refresh endpoint. This endpoint, included in WHITELIST_URLS, requires no authentication and allows an attacker with a credential ID to access the victim's connected service and potentially exhaust refresh-token quota. The vulnerability affects [truncated]

CRITICAL FlowiseAI CVE published 2026-08-04

CVE-2026-70477

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:54.473Z and has not been modified since then. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the b [truncated]

HIGH FlowiseAI CVE published 2026-08-04

CVE-2026-70476

CVE-2026-70476 is a high-severity vulnerability in Flowise, a drag & drop user interface for building customized large language model flows. The issue, fixed in version 3.1.3, allows authenticated attackers to perform unauthorized Stripe subscription operations on other tenants by manipulating subscriptionId values in organization billing endpoints. This can lead to financial impact and service disruption [truncated]

HIGH FlowiseAI CVE published 2026-08-04

CVE-2026-70474

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. The CVE record was published on 2026-08-04T19:16:54.977Z and has not been modified since then. The NVD entry is currently 7.6 HIGH. This vulnerability affects Flowise users and administrators, allowing any authenticated user to initiate OAuth2 flows against credentials belonging to other workspaces, and all [truncated]

HIGH FlowiseAI CVE published 2026-08-04

CVE-2026-69258

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T17:17:01.280Z and has not been modified since then. The NVD entry is currently Received. Flowise, a drag & drop user interface to build a customized large language model flow, had an unauthenticated POST /api/v1/prediction/:id endpoint that accepted an overrideConfig object and spread it into int [truncated]

CRITICAL FlowiseAI CVE published 2026-08-04

CVE-2026-69256

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T17:17:00.707Z and has not been modified since then. The NVD entry is currently Received. The CSVAgent node in Flowise, a drag & drop user interface for building customized large language model flows, was vulnerable to code execution. An authenticated user who could create or modify a chatflow cou [truncated]

HIGH FlowiseAI CVE published 2026-06-08

CVE-2026-46480

CVE-2026-46480 is a HIGH-severity vulnerability in Flowise, a drag & drop user interface for building customized large language model flows. The issue, patched in version 3.1.2, allows cross-workspace evaluator takeover due to evaluator create and update mass-assignment.

HIGH FlowiseAI CVE published 2026-06-08

CVE-2026-46479

CVE-2026-46479 is a high-severity vulnerability in Flowise, a drag & drop user interface to build customized large language model flows. The vulnerability, with a CVSS score of 7.7, allows for cross-workspace evaluation takeover due to mass-assignment issues in evaluation create and update operations. This issue was patched in version 3.1.2 of Flowise.

HIGH FlowiseAI CVE published 2026-06-08

CVE-2026-46478

CVE-2026-46478 is a high-severity vulnerability in Flowise, a drag & drop user interface for building customized large language model flows. The issue, tracked as CWE-915, allows for cross-workspace row takeover due to DatasetRow create and update mass-assignment vulnerabilities prior to version 3.1.2. This vulnerability has a CVSS score of 7.7 and is considered HIGH severity.

HIGH FlowiseAI CVE published 2026-06-08

CVE-2026-46477

CVE-2026-46477 is a HIGH severity vulnerability in Flowise, a drag & drop user interface to build a customized large language model flow. The vulnerability allows for cross-workspace dataset takeover due to dataset create and update mass-assignment. This issue was patched in version 3.1.2.

HIGH FlowiseAI CVE published 2026-06-08

CVE-2026-46476

CVE-2026-46476 is a HIGH severity vulnerability in Flowise, a drag & drop user interface to build customized large language model flows. The issue allows for a cross-workspace template takeover due to CustomTemplate create and update mass-assignment. This vulnerability was patched in version 3.1.2.

HIGH FlowiseAI CVE published 2026-06-08

CVE-2026-46475

CVE-2026-46475 is a HIGH-severity vulnerability in Flowise, a drag & drop user interface for building customized large language model flows. The issue, patched in version 3.1.2, allows for cross-workspace assistant takeover due to mass-assignment vulnerabilities in assistant create and update functions.

HIGH FlowiseAI CVE published 2026-06-08

CVE-2026-46444

A vulnerability was discovered in Flowise, a drag & drop user interface for building customized large language model flows. The issue, tracked as CVE-2026-46444, affects versions prior to 3.1.2 and has a CVSS score of 8.7, indicating a high severity. The vulnerability arises from the lack of authentication middleware for all CRUD endpoints of OpenAI Assistants Vector Store, specifically the /api/v1/openai [truncated]

HIGH FlowiseAI CVE published 2026-06-08

CVE-2026-46443

CVE-2026-46443 is a high-severity vulnerability in Flowise, a drag & drop user interface for building customized large language model flows. The issue allows an attacker to access encrypted data when credentials are fetched with a credentialName filter parameter. This vulnerability has been patched in version 3.1.2.

CRITICAL FlowiseAI CVE published 2026-06-08

CVE-2026-46442

CVE-2026-46442 is a critical vulnerability in Flowise, a drag & drop user interface to build customized large language model flows. Prior to version 3.1.2, the POST /api/v1/node-custom-function endpoint lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScript to the Custom JS Function node. When E2B_APIKEY is not configured, Flowise executes this code insi [truncated]

HIGH FlowiseAI CVE published 2026-06-08

CVE-2026-46441

A high-severity vulnerability was discovered in FlowiseAI, a drag-and-drop user interface for building customized large language model flows. The issue, tracked as CVE-2026-46441, is a mass assignment vulnerability in the assistant update endpoint. This vulnerability allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and updatedDate when updating an assista [truncated]

CRITICAL FlowiseAI CVE published 2026-06-08

CVE-2026-46440

A critical vulnerability, CVE-2026-46440, was found in Flowise, a drag & drop user interface to build a customized large language model flow. The vulnerability has a CVSS score of 9.1 and was patched in version 3.1.2. The issue involves the checkBasicAuth endpoint validating credentials in plaintext without rate limiting and with direct comparison.

HIGH FlowiseAI CVE published 2026-06-08

CVE-2026-42863

A mass assignment vulnerability exists in the chatflow update endpoint of FlowiseAI Flowise prior to version 3.1.2. This vulnerability allows an authenticated user to manipulate internal attributes of a chatflow and reassign it to another workspace, potentially leading to cross-workspace resource reassignment and unauthorized modification of deployment and visibility settings.

HIGH FlowiseAI CVE published 2026-06-08

CVE-2026-42862

CVE-2026-42862 is a high-severity vulnerability in FlowiseAI Flowise, a drag-and-drop user interface for building customized large language model flows. The issue, patched in version 3.1.2, allows authenticated users to manipulate the workspaceId field and reassign tools to arbitrary workspaces, breaking tenant isolation in multi-workspace environments.

HIGH FlowiseAI CVE published 2026-06-08

CVE-2026-42861

A high-severity vulnerability exists in FlowiseAI Flowise, allowing authenticated users to manipulate workspace IDs and reassign variables to arbitrary workspaces. This issue, CVE-2026-42861, has been patched in version 3.1.2.

MEDIUM FlowiseAI CVE published 2026-05-11

CVE-2026-43995

CVE-2026-43995 affects Flowise versions before 3.1.0. According to the vendor advisory and NVD, several tool implementations used raw HTTP clients directly instead of the secured wrapper, which NVD maps to CWE-918. The issue is fixed in Flowise 3.1.0. With a CVSS 5.3 Medium score and network-based attack conditions, this is a practical patching and configuration review item for anyone exposing affected Fl [truncated]