LIVE · cybersecurity feed
Live wire
vendor

Flowiseai

37 CVEs published in the last four months. Exploited flaws first.

Critical15
High22
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2025-7133810criticalflowiseFlowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows 72d ago
CVE-2026-464429.9criticalflowiseFlowise is a drag & drop user interface to build a customized large language model flow.89d ago
CVE-2026-736029.9criticalflowiseFlowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticat23d ago
CVE-2026-562749.9criticalflowiseFlowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due t74d ago
CVE-2026-439959.8criticalflowiseFlowise is a drag & drop user interface to build a customized large language model flow.117d ago
CVE-2025-713339.8criticalflowiseFlowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments e72d ago
CVE-2025-713349.8criticalflowiseFlowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to 72d ago
CVE-2025-713369.8criticalflowiseFlowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution v72d ago
CVE-2026-562719.8criticalflowiseFlowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token',55d ago
CVE-2026-734879.8criticalflowiseFlowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allo23d ago
CVE-2026-428619.6criticalflowiseFlowise is a drag & drop user interface to build a customized large language model flow.89d ago
CVE-2026-464419.6criticalflowiseFlowise is a drag & drop user interface to build a customized large language model flow.89d ago
CVE-2026-464409.1criticalflowiseFlowise is a drag & drop user interface to build a customized large language model flow.89d ago
CVE-2025-713279.1criticalflowiseFlowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that 72d ago
CVE-2026-562789.1criticalflowiseFlowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for t67d ago
CVE-2026-464788.8highflowiseFlowise is a drag & drop user interface to build a customized large language model flow.89d ago
CVE-2026-464798.8highflowiseFlowise is a drag & drop user interface to build a customized large language model flow.89d ago
CVE-2026-464808.8highflowiseFlowise is a drag & drop user interface to build a customized large language model flow.89d ago
CVE-2026-734858.8highflowiseFlowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticate23d ago
CVE-2026-734868.8highflowiseFlowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that 23d ago
CVE-2026-736018.8highflowiseFlowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP23d ago
CVE-2026-734838.8highflowiseFlowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowis23d ago
CVE-2026-464448.8highflowiseFlowise is a drag & drop user interface to build a customized large language model flow.89d ago
CVE-2026-464758.8highflowiseFlowise is a drag & drop user interface to build a customized large language model flow.89d ago
CVE-2026-464768.8highflowiseFlowise is a drag & drop user interface to build a customized large language model flow.89d ago
CVE-2026-464778.8highflowiseFlowise is a drag & drop user interface to build a customized large language model flow.89d ago
CVE-2025-713378.3highflowiseFlowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability.74d ago
CVE-2025-713288.3highflowiseFlowise before 3.0.10 contains an unverified password change vulnerability.72d ago
CVE-2026-428638.1highflowiseFlowise is a drag & drop user interface to build a customized large language model flow.89d ago
CVE-2026-734848.1highflowiseFlowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native 23d ago
CVE-2025-713358.1highflowiseFlowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session toke72d ago
CVE-2026-676207.7highflowiseFlowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSe28d ago
CVE-2026-562687.7highflowiseFlowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endp75d ago
CVE-2025-713247.5highflowiseFlowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-uplo72d ago
CVE-2026-562707.5highflowiseFlowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/73d ago
CVE-2026-719627.5highflowiseFlowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assi26d ago
CVE-2026-562757.1highflowiseFlowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows att74d ago

Filter the full tracker by Flowiseai