Flowiseai
Flowiseai Flowise: vulnerabilidades y CVE
Flowiseai Flowise tiene 150 vulnerabilidades publicadas, 133 de ellas en los últimos 12 meses. 44 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE150
Últimos 12 meses133
Críticas44
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-100610 | Alta (7.7) | 0.27% | — | 26 sept 2026 | Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permission checks, and the backing service performs no workspace or ownership validation.… |
| CVE-2026-100609 | Alta (7.6) | 0.23% | — | 26 sept 2026 | Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on the requesting user's workspace (findOneBy({ id: credentialId }) with no workspaceId condition) in… |
| CVE-2026-100608 | Alta (8.7) | 0.27% | — | 26 sept 2026 | Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode with the dashboard enabled and not in cloud mode (MODE=queue, ENABLE_BULLMQ_DASHBOARD=true, and… |
| CVE-2026-100607 | Crítica (9.2) | 0.29% | — | 26 sept 2026 | Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing provider or subject identifier bindings, allowing attackers to authenticate as any existing user by claiming their email at any… |
| CVE-2026-100606 | Crítica (9.2) | 0.37% | — | 26 sept 2026 | Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When an SSO callback arrives with an email matching a user whose status is INVITED,… |
| CVE-2026-100605 | Alta (7.5) | 0.22% | — | 26 sept 2026 | Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API keys to read and delete chat history. Attackers with valid but low-privileged API keys can access… |
| CVE-2026-91938 | Alta (7.6) | 0.37% | — | 15 sept 2026 | Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch… |
| CVE-2026-91936 | Alta (8.3) | 0.46% | — | 15 sept 2026 | Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write… |
| CVE-2026-91934 | Alta (8.7) | 0.74% | — | 15 sept 2026 | Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious… |
| CVE-2026-91933 | Alta (7.6) | 0.35% | — | 15 sept 2026 | Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped… |
| CVE-2026-91932 | Crítica (9) | 0.73% | — | 15 sept 2026 | Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path… |
| CVE-2026-91937 | Alta (8.7) | 0.47% | — | 15 sept 2026 | Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the… |
| CVE-2026-91935 | Alta (8.7) | 0.39% | — | 15 sept 2026 | Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can… |
| CVE-2026-91931 | Crítica (9) | 0.68% | — | 15 sept 2026 | Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter.… |
| CVE-2026-91930 | Alta (7.7) | 0.40% | — | 15 sept 2026 | Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as… |
| CVE-2026-91929 | Alta (7.6) | 0.35% | — | 15 sept 2026 | Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces,… |
| CVE-2026-90580 | Baja (2.1) | 0.41% | — | 13 sept 2026 | A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The… |
| CVE-2026-90535 | Media (6.3) | 0.48% | — | 12 sept 2026 | Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification.… |
| CVE-2026-90534 | Media (6.1) | 0.37% | — | 12 sept 2026 | Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission check and invokes… |
| CVE-2026-90533 | Media (6) | 0.34% | — | 12 sept 2026 | Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user record including… |
| CVE-2026-52098 | Crítica (9.8) | 1.1% | — | 10 sept 2026 | An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint |
| CVE-2026-73604 | Alta (7.1) | 0.41% | — | 13 ago 2026 | Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view… |
| CVE-2026-73603 | Media (6.3) | 0.33% | — | 13 ago 2026 | Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited… |
| CVE-2026-73602 | Crítica (9) | 0.83% | — | 13 ago 2026 | Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a… |
| CVE-2026-73601 | Crítica (9) | 1.1% | — | 13 ago 2026 | Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating… |
| CVE-2026-73488 | Media (6) | 0.37% | — | 13 ago 2026 | Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers'… |
| CVE-2026-73487 | Crítica (9) | 0.77% | — | 13 ago 2026 | Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit… |
| CVE-2026-73486 | Crítica (9) | 0.66% | — | 13 ago 2026 | Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a static regex… |
| CVE-2026-73485 | Crítica (9) | 0.60% | — | 13 ago 2026 | Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through… |
| CVE-2026-73484 | Alta (8.6) | 0.43% | — | 13 ago 2026 | Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit this… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.