PatchSiren

FlowiseAI CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH FlowiseAI CVE published 2026-09-15

CVE-2026-91937

CVE-2026-91937 debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T16:17:45.170Z and has not been modified since then. The NVD entry is currently Deferred. Defenders responsible for Flowise deployments, particularly those using versions prior to 3.1.4, should assess exposure and prioritize remediation to prevent potential data exposure. The vulnerability allows unauthen [truncated]

CRITICAL FlowiseAI CVE published 2026-09-15

CVE-2026-91931

CVE-2026-91931 debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T16:17:43.883Z and has not been modified since then. The NVD entry is currently Deferred. The vulnerability is a remote code execution vulnerability in the Custom MCP node of Flowise before version 3.1.4. This vulnerability allows authenticated attackers to execute arbitrary code by supplying npx package [truncated]

HIGH FlowiseAI CVE published 2026-09-15

CVE-2026-91930

CVE-2026-91930 debrief: Flowise before 3.1.4 has a critical vulnerability allowing authenticated users to gain administrative access to victim organizations by exploiting insufficient tenant isolation. This vulnerability affects Flowise deployments with multi-tenant setups, particularly those using enterprise organization and workspace membership APIs. Attackers can add themselves as organization owners, [truncated]

HIGH FlowiseAI CVE published 2026-09-15

CVE-2026-91929

CVE-2026-91929 debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T16:17:43.187Z and has not been modified since then. The NVD entry is currently Deferred. Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces [truncated]

CRITICAL FlowiseAI CVE published 2026-09-10

CVE-2026-52098

CVE-2026-52098 is a critical vulnerability in Flowise 3.1.2 that allows remote attackers to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint. The CVSS score is 9.8, indicating a high severity. The CVE record was published on 2026-09-10T17:17:04.940Z and last modified on 2026-09-15T19:09:25.387Z. The NVD entry is currently Analyzed.

HIGH FlowiseAI CVE published 2026-08-13

CVE-2026-73604

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T12:17:24.750Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with creden [truncated]

CRITICAL FlowiseAI CVE published 2026-08-13

CVE-2026-73602

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T12:17:24.480Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. The CVE-2026-73602 vulnerability in Flowise before 3.1.3 is a critical sandbox escape issue in the vm2 JavaScript sandbox. This allows authenticated users to execute arbitrary code by exploiting a by [truncated]

CRITICAL FlowiseAI CVE published 2026-08-13

CVE-2026-73601

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T12:17:24.353Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands [truncated]

MEDIUM FlowiseAI CVE published 2026-08-13

CVE-2026-73488

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T12:17:24.220Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access [truncated]

CRITICAL FlowiseAI CVE published 2026-08-13

CVE-2026-73487

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T12:17:24.083Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. The Flowise application before version 3.1.3 contains a regex-based Python code validator bypass vulnerability in its CSV and Airtable Agent nodes. This vulnerability allows unauthenticated attackers [truncated]

CRITICAL FlowiseAI CVE published 2026-08-13

CVE-2026-73486

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T12:17:23.947Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. The CVE-2026-73486 vulnerability in Flowise before 3.1.3 allows authenticated attackers to execute arbitrary Python code via the CSV Agent node's customReadCSV parameter. The vulnerability has a CVSS [truncated]

CRITICAL FlowiseAI CVE published 2026-08-13

CVE-2026-73485

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T12:17:23.807Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This critical vulnerability in Flowise before version 3.1.3 allows unauthenticated attackers to execute arbitrary Python code through obfuscation techniques in the Airtable Agent node. The vulnerabil [truncated]

HIGH FlowiseAI CVE published 2026-08-13

CVE-2026-73484

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T12:17:23.677Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. Flowise versions prior to 3.1.3 contain a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. This allows [truncated]

CRITICAL FlowiseAI CVE published 2026-08-13

CVE-2026-73483

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T12:17:23.540Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. Flowise versions <= 3.1.2 contain a sandbox escape vulnerability in the vm2/@flowiseai/nodevm JavaScript sandbox, allowing authenticated users with access to the /api/v1/node-custom-function endpoint [truncated]

HIGH FlowiseAI CVE published 2026-08-10

CVE-2026-71962

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T19:17:31.400Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint. This allows unauthenticated attackers to access privat [truncated]

MEDIUM FlowiseAI CVE published 2026-08-08

CVE-2026-67620

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts. The DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200. This allows authenticated attackers to force the server to issue arbitrary GET requests to cloud instance metadata services, potentially [truncated]

HIGH FlowiseAI CVE published 2026-08-06

CVE-2026-70636

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:18:28.150Z and has not been modified since then. CVE-2026-70636 is an authentication bypass vulnerability in Flowise versions up to 3.1.4. The vulnerability allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the au [truncated]

HIGH FlowiseAI CVE published 2026-08-06

CVE-2026-67622

CVE-2026-67622 debrief based on the supplied source corpus. Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration. This vulnerability allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification. The vulnerability i [truncated]

HIGH FlowiseAI CVE published 2026-08-06

CVE-2026-67621

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:18:22.717Z and has not been modified since then. CVE-2026-67621 is a missing authorization vulnerability in Flowise through version 3.1.4. The vulnerability allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Att [truncated]

CRITICAL FlowiseAI CVE published 2026-08-04

CVE-2026-70478

CVE-2026-70478 Flowise OAuth2 Credential Refresh Endpoint Vulnerability. Flowise, a drag & drop user interface to build customized large language model flows, has a critical vulnerability in its OAuth2 credential refresh endpoint. The endpoint, which requires no authentication, can decrypt stored credentials and send refresh requests to the configured OAuth provider. This issue allows an attacker with a c [truncated]

CRITICAL FlowiseAI CVE published 2026-08-04

CVE-2026-70477

CVE-2026-70477 Flowise Prompt Injection. Flowise, a drag & drop user interface for building customized large language model flows, is vulnerable to a prompt injection attack. This critical vulnerability, identified as CVE-2026-70477, allows an attacker to inject a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment prior to version 3.1.3. The fl [truncated]

HIGH FlowiseAI CVE published 2026-08-04

CVE-2026-70476

CVE-2026-70476 Flowise unauthorized Stripe subscription operations. Flowise, a drag & drop user interface to build customized large language model flows, has a vulnerability in several organization billing endpoints. Prior to version 3.1.3, these endpoints accept attacker-controlled Stripe subscriptionId values without verifying the identifier belongs to the authenticated user's organization. This allows [truncated]

HIGH FlowiseAI CVE published 2026-08-04

CVE-2026-70475

CVE-2026-70475 Flowise Privilege Escalation Vulnerability. Flowise users and administrators should be aware of a high-severity vulnerability allowing authenticated users to escalate privileges and manipulate workflow execution results. The vulnerability exists in the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts, which lacks the checkAnyPermission() middleware. This [truncated]

HIGH FlowiseAI CVE published 2026-08-04

CVE-2026-70474

CVE-2026-70474 Flowise OAuth2 credential endpoint vulnerability allows unauthorized access and token manipulation. The affected routes include /api/v1/oauth2-credential/authorize/<VICTIM_CREDENTIAL_UUID>, /api/v1/oauth2-credential/callback?code=ATTACKER_AUTH_CODE&state=<VICTIM_CREDENTIAL_UUID>, and /api/v1/oauth2-credential/refresh/<VICTIM_CREDENTIAL_UUID>. This issue is fixed in version 3.1.3.

HIGH FlowiseAI CVE published 2026-08-04

CVE-2026-70473

CVE-2026-70473 Flowise API History Exposure. Flowise, a drag-and-drop user interface for building customized large language model (LLM) flows, has a vulnerability in its API endpoint GET /api/v1/upsert-history. Prior to version 3.1.3, this endpoint returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response can exceed 100MB and includes [truncated]

HIGH FlowiseAI CVE published 2026-08-04

CVE-2026-70471

CVE-2026-70471 Flowise Variables API bypass allows unauthorized exposure of sensitive workspace variables. Affected product: Flowise versions prior to 3.1.3. Vulnerability class: Variables API bypass. Likely operational impact: Potential exposure of sensitive data such as database passwords, JWT secrets, SMTP passwords, and cloud keys. Source-confidence limits: High confidence based on CVE record and NVD [truncated]

CRITICAL FlowiseAI CVE published 2026-08-04

CVE-2026-70470

CVE-2026-70470 is a critical vulnerability in Flowise, a drag-and-drop user interface for building customized large language model flows. The vulnerability allows for arbitrary Python execution inside Pyodide and full OS command execution on the Flowise host via Pyodide js module interop. This is possible due to a bypass of the validatePythonCodeForDataFrame function in packages/components/src/pythonCodeV [truncated]

CRITICAL FlowiseAI CVE published 2026-08-04

CVE-2026-69264

CVE-2026-69264 is a critical vulnerability in Flowise, a platform for building AI workflows. An attacker can exploit this vulnerability by crafting a malicious CSV file, which can lead to remote code execution on the host system. The vulnerability exists in versions prior to 3.1.3 and is fixed in version 3.1.3. Flowise users and administrators should assess their exposure to this vulnerability and take st [truncated]

HIGH FlowiseAI CVE published 2026-08-04

CVE-2026-69263

A vulnerability in Flowise, a drag-and-drop user interface for building customized large language model flows, allows for auto-installation and execution of packages via the npm_config_yes environment variable. This issue, fixed in version 3.1.3, has a CVSS score of 8.7 and is considered high severity. The vulnerability exists because the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but [truncated]

CRITICAL FlowiseAI CVE published 2026-08-04

CVE-2026-69259

CVE-2026-69259 is a critical vulnerability in Flowise, a drag-and-drop user interface for building customized large language model flows. An authenticated attacker could exploit this vulnerability to write a SQLite database to arbitrary paths, potentially leading to code execution. The vulnerability is caused by the SQLite Record Manager node in Flowise accepting user-controlled additional configuration, [truncated]