OsVault/npm/flowise
npm

flowise

53 known vulnerabilities · 0 critical · 3 high

GHSA-28g4-38q8-3cwc

Flowise: Cypher Injection in GraphCypherQAChain

Published Apr 16, 2026
GHSA-4jpm-cgx2-8h37

Flowise: Sensitive Data Leak in public-chatbotConfig

Published Apr 16, 2026
GHSA-5fw2-mwhh-9947

Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials

Published Apr 17, 2026
CVE-2024-36422MEDIUM

Flowise Cross-site Scripting in api/v1/chatflows/id

Published Aug 5, 2024
GHSA-2qqc-p94c-hxwh

Flowise: Weak Default Express Session Secret

Published Apr 16, 2026
GHSA-6f7g-v4pp-r667

Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow in Flowise

Published Apr 16, 2026
GHSA-6pcv-j4jx-m4vx

Flowise: Unauthenticated Information Disclosure of OAuth Secrets (Cleartext) via GET Request

Published Apr 16, 2026
GHSA-6r77-hqx7-7vw8

Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains

Published Apr 16, 2026
CVE-2025-57164

FlowiseAI Pre-Auth Arbitrary Code Execution

Published Sep 15, 2025
CVE-2025-26319

FlowiseAI Flowise arbitrary file upload vulnerability

Published Mar 5, 2025
CVE-2026-30822

Flowise Allows Mass Assignment in `/api/v1/leads` Endpoint

Published Mar 6, 2026
CVE-2024-37145MEDIUM

Flowise Cross-site Scripting in /api/v1/chatflows-streaming/id

Published Aug 5, 2024
GHSA-48m6-ch88-55mj

Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association

Published Apr 16, 2026
GHSA-9hrv-gvrv-6gf2

Flowise Execute Flow function has an SSRF vulnerability

Published Apr 16, 2026
GHSA-qqvm-66q4-vf5c

Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)

Published Apr 16, 2026
GHSA-c9gw-hvqq-f33r

Flowise: Authenticated RCE Via MCP Adapters

Published Apr 16, 2026
CVE-2024-36423MEDIUM

Flowise Cross-site Scripting in /api/v1/public-chatflows/id

Published Aug 5, 2024
CVE-2026-30820

Flowise has Authorization Bypass via Spoofed x-request-from Header

Published Mar 6, 2026
GHSA-rh7v-6w34-w2rr

Flowise: File Upload Validation Bypass in createAttachment

Published Apr 16, 2026
GHSA-w6v6-49gh-mc9w

Flowise: Path Traversal in Vector Store basePath

Published Apr 16, 2026
CVE-2025-55346

Flowise vulnerable to RCE via Dynamic function constructor injection

Published Oct 6, 2025
GHSA-xhmj-rg95-44hv

Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox

Published Apr 16, 2026
CVE-2025-29192

Flowise Stored XSS vulnerability through logs in chatbot

Published Oct 3, 2025
GHSA-v38x-c887-992f

Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability

Published Apr 18, 2026
CVE-2024-31621HIGH

Flowise vulnerable to code injection via api/v1

Published Apr 29, 2024
CVE-2025-61687

FlowiseAI/Flosise has File Upload vulnerability

Published Oct 8, 2025
GHSA-3hjv-c53m-58jj

Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

Published Apr 21, 2026
GHSA-3prp-9gf7-4rxx

Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)

Published Apr 17, 2026
GHSA-f228-chmx-v6j6

Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.

Published Apr 16, 2026
GHSA-f6hc-c5jr-878p

Flowise: resetPassword Authentication Bypass Vulnerability

Published Apr 16, 2026
CVE-2024-8182

Flowise Unauthenticated Denial of Service (DoS) vulnerability

Published Aug 27, 2024
GHSA-9wc7-mj3f-74xv

Flowise: Code Injection in CSVAgent leads to Authenticated RCE

Published Apr 16, 2026
GHSA-m7mq-85xj-9x33

Flowise: Weak Default Token Hash Secret

Published Apr 16, 2026
GHSA-w47f-j8rh-wx87

Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs

Published Apr 17, 2026
GHSA-x2g5-fvc2-gqvp

Flowise has Insufficient Password Salt Rounds

Published Mar 5, 2026
GHSA-cvrr-qhgw-2mm6

Flowise: Parameter Override Bypass Remote Command Execution

Published Apr 16, 2026
CVE-2026-30823

Flowise has IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration

Published Mar 6, 2026
CVE-2024-36420HIGH

Flowise Path Injection at /api/v1/openai-assistants-file

Published Aug 5, 2024
GHSA-j44m-5v8f-gc9c

Flowise is vulnerable to arbitrary file exposure through its ReadFileTool

Published Oct 10, 2025
CVE-2026-30821

Flowise has Arbitrary File Upload via MIME Spoofing

Published Mar 6, 2026
GHSA-jc5m-wrp2-qq38

Flowise Vulnerable to PII Disclosure on Unauthenticated Forgot Password Endpoint

Published Mar 5, 2026
CVE-2024-9148

Flowise and Flowise Chat Embed vulnerable to Stored Cross-site Scripting

Published Sep 25, 2024
GHSA-x5w6-38gp-mrqh

Flowise: Password Reset Link Sent Over Unsecured HTTP

Published Apr 16, 2026
CVE-2026-30824

Flowise Missing Authentication on NVIDIA NIM Endpoints

Published Mar 6, 2026
GHSA-2x8m-83vc-6wv4

Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)

Published Apr 16, 2026
CVE-2025-61913

Flowise is vulnerable to arbitrary file write through its WriteFileTool

Published Oct 9, 2025
CVE-2024-36421HIGH

Flowise Cors Misconfiguration in packages/server/src/index.ts

Published Aug 5, 2024
GHSA-cc4f-hjpj-g9p8

Flowise: Weak Default JWT Secrets

Published Apr 16, 2026
CVE-2026-31829

Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access

Published Mar 11, 2026
CVE-2025-34267

Flowise: Authenticated Command Execution and Sandbox Bypass via Puppeteer and Playwright Packages

Published Oct 14, 2025
CVE-2024-37146MEDIUM

Flowise Cross-site Scripting in/api/v1/credentials/id

Published Aug 5, 2024
CVE-2025-50538

Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel

Published Oct 3, 2025
CVE-2025-29189

Flowise Vulnerable to SQL Injection via `tableName` Parameter

Published Apr 9, 2025
Check your entire dependency tree at onceRun dependency scan →