VYPR

Flowise

by Flowiseai

npm: flowise

Source repositories

CVEs (129)

  • CVE-2026-70471HigAug 4, 2026
    risk 0.00cvss epss 0.00

    Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protected Variables API. Variables for the active…

  • CVE-2026-69251CriAug 4, 2026
    risk 0.00cvss epss 0.01

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSource options through the additionalConfig input in…

  • CVE-2026-56271CriJul 12, 2026
    risk 0.00cvss 9.8epss 0.00

    Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware…

  • CVE-2026-56273MedJul 8, 2026
    risk 0.00cvss 6.5epss 0.00

    Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that accept unsanitized basePath parameters from authenticated users. Attackers with valid API tokens can write vector store data to arbitrary filesystem locations,…

  • CVE-2026-56278CriJun 30, 2026
    risk 0.00cvss 9.1epss 0.00

    Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set (packages/server/src/enterprise/middleware/passport/index.ts). Because…

  • CVE-2026-56277MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    Flowise before 3.1.2 sets Access-Control-Allow-Origin to a hardcoded wildcard (*) on its text-to-speech (TTS) generation endpoint (packages/server/src/controllers/text-to-speech/index.ts), independent of the server's configured CORS policy. This bypasses the server's otherwise…

  • CVE-2025-71338CriJun 25, 2026
    risk 0.00cvss 10.0epss 0.01

    Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fileName parameters with ../ sequences to overwrite critical…

  • CVE-2025-71333CriJun 25, 2026
    risk 0.00cvss 9.8epss 0.01

    Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary…

  • CVE-2025-71327CriJun 25, 2026
    risk 0.00cvss 9.1epss 0.01

    Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint to register arbitrary accounts and authenticate to the system,…

Page 7 of 7