Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Flowise — Vulnerabilities & Security Advisories 20

Browse all 20 CVE security advisories affecting Flowise. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page serves as a comprehensive vulnerability aggregation resource for Flowise, focusing on security weaknesses associated with its open-source LLM development platform. It collects data on a wide range of common vulnerability types, including cross-site scripting, path traversal, and authorization bypasses, covering security advisories and issue reports from 2023 to the present. By utilizing this resource, users can effectively track a vendor's advisory history to stay informed about emerging threats and remediation efforts. The page also provides a deeper understanding of specific weakness classes by illustrating how they manifest within the Flowise ecosystem, helping developers and security professionals identify common patterns and implementation flaws. Additionally, users can look up a product's vulnerability history to assess the long-term security posture of the software and evaluate the effectiveness of past patches. This historical context is crucial for risk assessment, allowing teams to prioritize updates and mitigate potential exposure to known exploits. The information presented here is intended to support informed decision-making regarding software procurement, maintenance, and security audits, ensuring that stakeholders have access to accurate and timely data. This consolidated view eliminates the need to search multiple disparate sources, providing a single, reliable reference point for all things related to Flowise security incidents and patches.

Top products by Flowise: Flowise
CVE IDTitleCVSSSeverityPublished
CVE-2025-71338 Flowise - Arbitrary File Write to Remote Code Execution via document-store API — FlowiseCWE-73 10.0 Critical2026-06-25
CVE-2025-71336 Flowise - Unsandboxed Remote Code Execution via Custom MCP — FlowiseCWE-78 9.8 Critical2026-06-25
CVE-2025-71334 Flowise - Arbitrary File Access via Missing Chat Flow ID Validation — FlowiseCWE-73 9.8 Critical2026-06-25
CVE-2025-71335 Flowise - Session Invalidation Failure After Password Change — FlowiseCWE-613 8.1 High2026-06-25
CVE-2025-71333 Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint — FlowiseCWE-73--2026-06-25
CVE-2025-71328 Flowise - Unverified Password Change via Account Settings — FlowiseCWE-620 8.3 High2026-06-25
CVE-2025-71327 Flowise - Authentication Bypass via Unprotected Registration Endpoint — FlowiseCWE-306 9.1 Critical2026-06-25
CVE-2025-71324 Flowise - Arbitrary File Read via chatId Parameter — FlowiseCWE-73 7.5 High2026-06-25
CVE-2026-56272 Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing — FlowiseCWE-916 4.1 Medium2026-06-24
CVE-2026-56270 Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint — FlowiseCWE-306 7.5 High2026-06-24
CVE-2026-56269 Flowise - Weak Default Token Hash Secret in JWT Token Encryption — FlowiseCWE-798 4.6 Medium2026-06-24
CVE-2025-71332 Flowise - SQL Injection in importChatflows API via chatflow.id Parameter — FlowiseCWE-89 6.5 Medium2026-06-24
CVE-2026-56275 Flowise - Server-Side Request Forgery via Execute Flow Base URL — FlowiseCWE-918--2026-06-23
CVE-2026-56274 Flowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess — FlowiseCWE-78 9.9 Critical2026-06-23
CVE-2025-71337 Flowise - Unverified Email Change via Account Profile Endpoint — FlowiseCWE-620 8.3 High2026-06-23
CVE-2026-56268 Flowise - Cross-Workspace Information Disclosure via chatflows/apikey Endpoint — FlowiseCWE-863 7.7 High2026-06-22
CVE-2026-56276 Flowise - Mass Assignment in PUT /api/v1/user Allows Password Hash Override — FlowiseCWE-915--2026-06-20
CVE-2026-56267 Flowise - PII Disclosure via Unauthenticated Forgot Password Endpoint — FlowiseCWE-200--2026-06-20
CVE-2025-71331 Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows — FlowiseCWE-80 6.1 Medium2026-06-20
CVE-2024-58351 Flowise - Remote Code Execution via overrideConfig Parameter — FlowiseCWE-94 9.8 Critical2026-06-20

This page lists every published CVE security advisory associated with Flowise. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.