{"data":{"ecosystem":"npm","name":"flowise","url":"https://aisecwatch.com/packages/npm/flowise","latestVersion":"3.1.4","firstReleaseAt":"2023-04-10T19:39:46.916Z","repository":null,"llm":{"exposure":"direct","depth":0,"integratedAt":"2024-03-12T17:32:08.881Z","integratedVersion":"1.6.1","sdks":["mcp","openai"],"path":[]},"authority":{"profile":["http","mcp_tools"],"fromDependencies":["npm:@modelcontextprotocol/sdk","npm:axios"]},"dependencies":[{"ecosystem":"npm","name":"flowise-components","versionSpec":"^3.1.4","scope":"runtime"},{"ecosystem":"npm","name":"@modelcontextprotocol/sdk","versionSpec":"1.29.0","scope":"runtime"},{"ecosystem":"npm","name":"openai","versionSpec":"6.19.0","scope":"runtime"},{"ecosystem":"npm","name":"async-mutex","versionSpec":"^0.4.0","scope":"runtime"},{"ecosystem":"npm","name":"@aws-sdk/client-secrets-manager","versionSpec":"^3.1014.0","scope":"runtime"},{"ecosystem":"npm","name":"axios","versionSpec":"1.15.0","scope":"runtime"},{"ecosystem":"npm","name":"bcryptjs","versionSpec":"^2.4.3","scope":"runtime"},{"ecosystem":"npm","name":"@bull-board/api","versionSpec":"^6.11.0","scope":"runtime"},{"ecosystem":"npm","name":"@bull-board/express","versionSpec":"^6.11.0","scope":"runtime"},{"ecosystem":"npm","name":"bullmq","versionSpec":"5.45.2","scope":"runtime"},{"ecosystem":"npm","name":"cache-manager","versionSpec":"^6.3.2","scope":"runtime"},{"ecosystem":"npm","name":"connect-pg-simple","versionSpec":"^10.0.0","scope":"runtime"},{"ecosystem":"npm","name":"connect-redis","versionSpec":"^8.0.1","scope":"runtime"},{"ecosystem":"npm","name":"connect-sqlite3","versionSpec":"^0.9.15","scope":"runtime"},{"ecosystem":"npm","name":"content-disposition","versionSpec":"0.5.4","scope":"runtime"},{"ecosystem":"npm","name":"cookie-parser","versionSpec":"^1.4.6","scope":"runtime"},{"ecosystem":"npm","name":"cors","versionSpec":"^2.8.5","scope":"runtime"},{"ecosystem":"npm","name":"crypto-js","versionSpec":"^4.1.1","scope":"runtime"},{"ecosystem":"npm","name":"csv-parser","versionSpec":"^3.0.0","scope":"runtime"},{"ecosystem":"npm","name":"dotenv","versionSpec":"^16.0.0","scope":"runtime"},{"ecosystem":"npm","name":"express","versionSpec":"^4.17.3","scope":"runtime"},{"ecosystem":"npm","name":"express-mysql-session","versionSpec":"^3.0.3","scope":"runtime"},{"ecosystem":"npm","name":"express-rate-limit","versionSpec":"^6.9.0","scope":"runtime"},{"ecosystem":"npm","name":"express-session","versionSpec":"^1.18.1","scope":"runtime"},{"ecosystem":"npm","name":"flowise-nim-container-manager","versionSpec":"^1.0.11","scope":"runtime"},{"ecosystem":"npm","name":"flowise-ui","versionSpec":"^3.1.4","scope":"runtime"},{"ecosystem":"npm","name":"geoip-lite","versionSpec":"^1.4.10","scope":"runtime"},{"ecosystem":"npm","name":"global-agent","versionSpec":"^3.0.0","scope":"runtime"},{"ecosystem":"npm","name":"@google-cloud/logging-winston","versionSpec":"^6.0.0","scope":"runtime"},{"ecosystem":"npm","name":"gulp","versionSpec":"^4.0.2","scope":"runtime"},{"ecosystem":"npm","name":"handlebars","versionSpec":"^4.7.8","scope":"runtime"},{"ecosystem":"npm","name":"http-errors","versionSpec":"^2.0.0","scope":"runtime"},{"ecosystem":"npm","name":"http-status-codes","versionSpec":"^2.3.0","scope":"runtime"},{"ecosystem":"npm","name":"jsonwebtoken","versionSpec":"^9.0.2","scope":"runtime"},{"ecosystem":"npm","name":"jwt-decode","versionSpec":"^4.0.0","scope":"runtime"},{"ecosystem":"npm","name":"@keyv/redis","versionSpec":"^4.2.0","scope":"runtime"},{"ecosystem":"npm","name":"langchainhub","versionSpec":"^0.0.11","scope":"runtime"},{"ecosystem":"npm","name":"lodash","versionSpec":"^4.17.21","scope":"runtime"},{"ecosystem":"npm","name":"moment","versionSpec":"^2.29.3","scope":"runtime"},{"ecosystem":"npm","name":"moment-timezone","versionSpec":"^0.5.34","scope":"runtime"},{"ecosystem":"npm","name":"multer","versionSpec":"^2.1.1","scope":"runtime"},{"ecosystem":"npm","name":"multer-azure-blob-storage","versionSpec":"^1.2.0","scope":"runtime"},{"ecosystem":"npm","name":"multer-cloud-storage","versionSpec":"^4.0.0","scope":"runtime"},{"ecosystem":"npm","name":"multer-s3","versionSpec":"^3.0.1","scope":"runtime"},{"ecosystem":"npm","name":"mysql2","versionSpec":"^3.11.3","scope":"runtime"},{"ecosystem":"npm","name":"nanoid","versionSpec":"3","scope":"runtime"},{"ecosystem":"npm","name":"node-cron","versionSpec":"^4.2.1","scope":"runtime"},{"ecosystem":"npm","name":"nodemailer","versionSpec":"^7.0.7","scope":"runtime"},{"ecosystem":"npm","name":"@oclif/core","versionSpec":"4.0.7","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/api","versionSpec":"1.9.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/auto-instrumentations-node","versionSpec":"^0.52.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/core","versionSpec":"1.27.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/exporter-metrics-otlp-grpc","versionSpec":"0.54.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/exporter-metrics-otlp-http","versionSpec":"0.54.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/exporter-metrics-otlp-proto","versionSpec":"0.54.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/exporter-trace-otlp-grpc","versionSpec":"0.54.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/exporter-trace-otlp-http","versionSpec":"0.54.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/exporter-trace-otlp-proto","versionSpec":"0.54.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/resources","versionSpec":"1.27.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/sdk-metrics","versionSpec":"1.27.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/sdk-node","versionSpec":"^0.54.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/sdk-trace-base","versionSpec":"1.27.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/semantic-conventions","versionSpec":"1.27.0","scope":"runtime"},{"ecosystem":"npm","name":"passport","versionSpec":"^0.7.0","scope":"runtime"},{"ecosystem":"npm","name":"passport-auth0","versionSpec":"^1.4.4","scope":"runtime"},{"ecosystem":"npm","name":"passport-cookie","versionSpec":"^1.0.9","scope":"runtime"},{"ecosystem":"npm","name":"passport-github","versionSpec":"^1.1.0","scope":"runtime"},{"ecosystem":"npm","name":"passport-google-oauth20","versionSpec":"^2.0.0","scope":"runtime"},{"ecosystem":"npm","name":"passport-jwt","versionSpec":"^4.0.1","scope":"runtime"},{"ecosystem":"npm","name":"passport-local","versionSpec":"^1.0.0","scope":"runtime"},{"ecosystem":"npm","name":"passport-openidconnect","versionSpec":"^0.1.2","scope":"runtime"},{"ecosystem":"npm","name":"pg","versionSpec":"^8.11.1","scope":"runtime"},{"ecosystem":"npm","name":"posthog-node","versionSpec":"^3.5.0","scope":"runtime"},{"ecosystem":"npm","name":"prom-client","versionSpec":"^15.1.3","scope":"runtime"},{"ecosystem":"npm","name":"rate-limit-redis","versionSpec":"^4.2.0","scope":"runtime"},{"ecosystem":"npm","name":"reflect-metadata","versionSpec":"^0.1.13","scope":"runtime"},{"ecosystem":"npm","name":"s3-streamlogger","versionSpec":"^1.11.0","scope":"runtime"},{"ecosystem":"npm","name":"sanitize-html","versionSpec":"^2.11.0","scope":"runtime"},{"ecosystem":"npm","name":"sqlite3","versionSpec":"^5.1.6","scope":"runtime"},{"ecosystem":"npm","name":"stripe","versionSpec":"^15.6.0","scope":"runtime"},{"ecosystem":"npm","name":"turndown","versionSpec":"^7.2.0","scope":"runtime"},{"ecosystem":"npm","name":"typeorm","versionSpec":"^0.3.28","scope":"runtime"},{"ecosystem":"npm","name":"@types/bcryptjs","versionSpec":"^2.4.6","scope":"runtime"},{"ecosystem":"npm","name":"@types/lodash","versionSpec":"^4.17.20","scope":"runtime"},{"ecosystem":"npm","name":"@types/passport","versionSpec":"^1.0.16","scope":"runtime"},{"ecosystem":"npm","name":"@types/passport-jwt","versionSpec":"^4.0.1","scope":"runtime"},{"ecosystem":"npm","name":"@types/passport-local","versionSpec":"^1.0.38","scope":"runtime"},{"ecosystem":"npm","name":"uuid","versionSpec":"^10.0.0","scope":"runtime"},{"ecosystem":"npm","name":"winston","versionSpec":"^3.9.0","scope":"runtime"},{"ecosystem":"npm","name":"winston-azure-blob","versionSpec":"^1.5.0","scope":"runtime"},{"ecosystem":"npm","name":"winston-daily-rotate-file","versionSpec":"^5.0.0","scope":"runtime"},{"ecosystem":"npm","name":"zod","versionSpec":"^3.25.76 || ^4","scope":"runtime"}],"advisories":[{"id":"5d60ea86-765c-4612-a285-f66230a9e617","url":"https://aisecwatch.com/issues/5d60ea86-765c-4612-a285-f66230a9e617","cveId":"CVE-2026-73483","title":"GHSA-9gvv-qjj3-2p6g: Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via Chromium","headline":null,"severity":"critical","publishedAt":"2026-10-07T16:17:02.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00621,"matchedBy":"ecosystem"},{"id":"d6c8e7b4-8965-4a01-82a0-6964e4b27faf","url":"https://aisecwatch.com/issues/d6c8e7b4-8965-4a01-82a0-6964e4b27faf","cveId":"CVE-2026-73487","title":"CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows…","headline":"Flowise Python code validator bypass in CSV and Airtable Agent nodes","severity":"critical","publishedAt":"2026-08-13T12:17:24.083Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)","flowise-components@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00961,"matchedBy":"ecosystem"},{"id":"15aa1daf-db37-4a20-aef1-32ed6ab70d05","url":"https://aisecwatch.com/issues/15aa1daf-db37-4a20-aef1-32ed6ab70d05","cveId":"CVE-2026-70478","title":"GHSA-qgvm-j2hm-6m38: Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service","headline":null,"severity":"critical","publishedAt":"2026-08-04T19:37:36.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00615,"matchedBy":"ecosystem"},{"id":"0d4bb36c-7798-4fc7-b3a1-343515949157","url":"https://aisecwatch.com/issues/0d4bb36c-7798-4fc7-b3a1-343515949157","cveId":"CVE-2026-70477","title":"GHSA-5xvg-pmgg-3mxr: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability","headline":null,"severity":"critical","publishedAt":"2026-08-04T19:29:26.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00814,"matchedBy":"ecosystem"},{"id":"24b11b12-aacf-4389-807d-853d304f57bc","url":"https://aisecwatch.com/issues/24b11b12-aacf-4389-807d-853d304f57bc","cveId":"CVE-2026-70476","title":"GHSA-gmmw-qg98-6j6p: Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation","headline":null,"severity":"high","publishedAt":"2026-08-04T19:24:07.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00518,"matchedBy":"ecosystem"},{"id":"0d2e72e4-46eb-4c4b-a7d3-59fe1db7f3ed","url":"https://aisecwatch.com/issues/0d2e72e4-46eb-4c4b-a7d3-59fe1db7f3ed","cveId":null,"title":"GHSA-8gj2-2cvc-6xx7: Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials","headline":null,"severity":"medium","publishedAt":"2026-08-04T19:19:44.000Z","affected":["flowise@<= 3.1.3 (fixed: 3.1.4)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"347f2f8a-8463-4f4e-b515-c05b822bd649","url":"https://aisecwatch.com/issues/347f2f8a-8463-4f4e-b515-c05b822bd649","cveId":"CVE-2026-70475","title":"GHSA-fm2f-4339-4p2f: Flowise: Missing Authorization on Execution Update Endpoint","headline":null,"severity":"high","publishedAt":"2026-08-04T19:18:47.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00458,"matchedBy":"ecosystem"},{"id":"e27d7d9b-ef3b-41a1-8742-5fb1b0c1b132","url":"https://aisecwatch.com/issues/e27d7d9b-ef3b-41a1-8742-5fb1b0c1b132","cveId":"CVE-2026-70474","title":"GHSA-wch5-xp77-fxg4: Flowise: Cross-Workspace OAuth2 Credential Metadata Leak","headline":null,"severity":"high","publishedAt":"2026-08-04T18:01:29.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00477,"matchedBy":"ecosystem"},{"id":"b945bdab-52b1-4ca8-bab3-b87ecde6ce33","url":"https://aisecwatch.com/issues/b945bdab-52b1-4ca8-bab3-b87ecde6ce33","cveId":null,"title":"GHSA-rwrp-9823-p2xq: Flowise: Incomplete Credential Redaction Exposes Secrets via API","headline":null,"severity":"medium","publishedAt":"2026-08-04T17:57:35.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"b04ac500-1e5a-4291-be0f-8724344bf759","url":"https://aisecwatch.com/issues/b04ac500-1e5a-4291-be0f-8724344bf759","cveId":"CVE-2026-70473","title":"GHSA-fr6g-7cq8-fg82: Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history","headline":null,"severity":"high","publishedAt":"2026-08-04T17:57:27.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00451,"matchedBy":"ecosystem"},{"id":"a5595c1b-54fa-4463-b1c5-a8f5ebfd376f","url":"https://aisecwatch.com/issues/a5595c1b-54fa-4463-b1c5-a8f5ebfd376f","cveId":"CVE-2026-70472","title":"GHSA-chm3-vqcf-52rx: Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store","headline":null,"severity":"high","publishedAt":"2026-08-04T17:51:48.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00515,"matchedBy":"ecosystem"},{"id":"ed4819d5-4302-4207-bf57-ea2e3b9707ce","url":"https://aisecwatch.com/issues/ed4819d5-4302-4207-bf57-ea2e3b9707ce","cveId":"CVE-2026-69264","title":"GHSA-4j8x-x6v7-w9rq: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation","headline":null,"severity":"critical","publishedAt":"2026-08-04T17:43:48.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.01112,"matchedBy":"ecosystem"},{"id":"c89f11a7-a283-4635-a897-4dbfc69ff1c9","url":"https://aisecwatch.com/issues/c89f11a7-a283-4635-a897-4dbfc69ff1c9","cveId":null,"title":"GHSA-88pr-878c-24wf: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys                                                                                                  ","headline":null,"severity":"high","publishedAt":"2026-08-04T17:43:45.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)","flowise-components@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"695345db-94e4-4294-b32b-dfac83838814","url":"https://aisecwatch.com/issues/695345db-94e4-4294-b32b-dfac83838814","cveId":"CVE-2026-70471","title":"GHSA-8r8h-6vcc-xhrv: Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure","headline":null,"severity":"high","publishedAt":"2026-08-04T17:43:36.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00412,"matchedBy":"ecosystem"},{"id":"89215702-e795-41b5-b522-ae8937becf80","url":"https://aisecwatch.com/issues/89215702-e795-41b5-b522-ae8937becf80","cveId":"CVE-2026-70470","title":"GHSA-52fh-8v99-63c2: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE","headline":null,"severity":"critical","publishedAt":"2026-08-04T17:31:09.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00972,"matchedBy":"ecosystem"},{"id":"a364d053-ab58-4a76-9620-5912d582b021","url":"https://aisecwatch.com/issues/a364d053-ab58-4a76-9620-5912d582b021","cveId":"CVE-2026-69263","title":"GHSA-xc48-889x-5qmw: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)","headline":null,"severity":"high","publishedAt":"2026-08-04T17:09:48.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00662,"matchedBy":"ecosystem"},{"id":"0b19c464-75ae-4273-b49c-ab731ca1d795","url":"https://aisecwatch.com/issues/0b19c464-75ae-4273-b49c-ab731ca1d795","cveId":"CVE-2026-69262","title":"GHSA-p5w8-m249-4r4v: Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type","headline":null,"severity":"high","publishedAt":"2026-08-04T16:50:32.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00524,"matchedBy":"ecosystem"},{"id":"ca5dbda8-1b8c-46fc-b04b-5c3d7a0758fa","url":"https://aisecwatch.com/issues/ca5dbda8-1b8c-46fc-b04b-5c3d7a0758fa","cveId":"CVE-2026-69259","title":"GHSA-x3hf-7cj6-3r4m: Flowise RCE via SQLite Record Manager Node","headline":null,"severity":"critical","publishedAt":"2026-08-04T16:05:10.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00821,"matchedBy":"ecosystem"},{"id":"303601b1-2a6a-4bcc-824f-6c7079a68c10","url":"https://aisecwatch.com/issues/303601b1-2a6a-4bcc-824f-6c7079a68c10","cveId":"CVE-2026-69258","title":"GHSA-6vh2-wg4h-4vwj: Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API","headline":null,"severity":"high","publishedAt":"2026-08-04T15:56:11.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00667,"matchedBy":"ecosystem"},{"id":"a4d8ecfb-e355-4d01-884f-5e843279c58d","url":"https://aisecwatch.com/issues/a4d8ecfb-e355-4d01-884f-5e843279c58d","cveId":"CVE-2026-69257","title":"GHSA-c6xh-wv4j-ppv5: Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses","headline":null,"severity":"high","publishedAt":"2026-08-04T15:51:58.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00428,"matchedBy":"ecosystem"},{"id":"413cb1e4-00ef-482e-a271-6f5afeecdfc6","url":"https://aisecwatch.com/issues/413cb1e4-00ef-482e-a271-6f5afeecdfc6","cveId":"CVE-2026-69256","title":"GHSA-x6vm-w76m-8j7g: Flowise: Remote Code Execution Vulnerability in CSVAgent","headline":null,"severity":"critical","publishedAt":"2026-08-04T15:46:20.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)","flowise-components@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.0101,"matchedBy":"ecosystem"},{"id":"5386ddd7-42db-4579-95af-dfee9174671d","url":"https://aisecwatch.com/issues/5386ddd7-42db-4579-95af-dfee9174671d","cveId":"CVE-2026-69255","title":"GHSA-vmv7-4m6c-3cg5: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified","headline":null,"severity":"critical","publishedAt":"2026-08-04T15:40:28.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00716,"matchedBy":"ecosystem"},{"id":"7ba8c4df-3b36-4f94-b37d-b1d5ddc2c30c","url":"https://aisecwatch.com/issues/7ba8c4df-3b36-4f94-b37d-b1d5ddc2c30c","cveId":"CVE-2026-69254","title":"GHSA-3769-jgqc-cxm7: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override","headline":null,"severity":"critical","publishedAt":"2026-08-04T15:29:12.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00691,"matchedBy":"ecosystem"},{"id":"f56747d0-7df8-4ff8-ba83-0d98d5fd9949","url":"https://aisecwatch.com/issues/f56747d0-7df8-4ff8-ba83-0d98d5fd9949","cveId":"CVE-2026-69253","title":"GHSA-wg86-r78f-74mp: Flowise Sandbox Escape to RCE","headline":null,"severity":"critical","publishedAt":"2026-08-04T15:13:33.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00664,"matchedBy":"ecosystem"},{"id":"42e970d0-c039-448c-9292-d30fb99d2c1d","url":"https://aisecwatch.com/issues/42e970d0-c039-448c-9292-d30fb99d2c1d","cveId":"CVE-2026-69252","title":"GHSA-wp74-f5hh-5f3r: Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization","headline":null,"severity":"high","publishedAt":"2026-08-04T14:54:03.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00544,"matchedBy":"ecosystem"},{"id":"6b03abdb-eb72-46c2-a9a6-779620d705b1","url":"https://aisecwatch.com/issues/6b03abdb-eb72-46c2-a9a6-779620d705b1","cveId":"CVE-2026-69251","title":"GHSA-g32j-mmxr-gfq5: Flowise RCE via TypeORM DataSource","headline":null,"severity":"critical","publishedAt":"2026-08-04T14:28:04.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.02742,"matchedBy":"ecosystem"},{"id":"714c15de-bf71-4af3-bf52-5d4177fb3b2d","url":"https://aisecwatch.com/issues/714c15de-bf71-4af3-bf52-5d4177fb3b2d","cveId":"CVE-2026-69250","title":"GHSA-r745-8hwv-h473: Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration","headline":null,"severity":"high","publishedAt":"2026-08-04T14:20:49.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00573,"matchedBy":"ecosystem"},{"id":"4fcf06b1-8582-4800-bad3-1aa49b264816","url":"https://aisecwatch.com/issues/4fcf06b1-8582-4800-bad3-1aa49b264816","cveId":null,"title":"GHSA-2364-jh4q-m9vm: Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint","headline":null,"severity":"medium","publishedAt":"2026-08-04T14:16:46.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"c0bcc338-cb9d-4ba2-ada9-3475ee728609","url":"https://aisecwatch.com/issues/c0bcc338-cb9d-4ba2-ada9-3475ee728609","cveId":"CVE-2026-46480","title":"CVE-2026-46480: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2…","headline":"Flowise evaluator mass-assignment allows cross-workspace takeover","severity":"high","publishedAt":"2026-06-08T16:16:42.600Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":0.00561,"matchedBy":"ecosystem"},{"id":"33b1c5e5-4f36-40c4-ab88-93920ff7d3ef","url":"https://aisecwatch.com/issues/33b1c5e5-4f36-40c4-ab88-93920ff7d3ef","cveId":"CVE-2026-46479","title":"CVE-2026-46479: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2…","headline":"Flowise mass-assignment flaw allows cross-workspace takeover","severity":"high","publishedAt":"2026-06-08T16:16:42.443Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":0.00561,"matchedBy":"ecosystem"},{"id":"c7c7f39f-ff38-42a3-90c4-af8caeeef03b","url":"https://aisecwatch.com/issues/c7c7f39f-ff38-42a3-90c4-af8caeeef03b","cveId":"CVE-2026-46478","title":"CVE-2026-46478: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2…","headline":"Flowise mass-assignment flaw enables cross-workspace row takeover","severity":"high","publishedAt":"2026-06-08T16:16:42.277Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":0.00561,"matchedBy":"ecosystem"},{"id":"d00dc0ef-153a-4191-87a5-446db15cbd6a","url":"https://aisecwatch.com/issues/d00dc0ef-153a-4191-87a5-446db15cbd6a","cveId":"CVE-2026-46477","title":"CVE-2026-46477: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2…","headline":"Flowise dataset mass-assignment allows cross-workspace takeover","severity":"high","publishedAt":"2026-06-08T16:16:42.097Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":0.00561,"matchedBy":"ecosystem"},{"id":"a318dacb-d6e7-45e7-829a-d90a82da319b","url":"https://aisecwatch.com/issues/a318dacb-d6e7-45e7-829a-d90a82da319b","cveId":"CVE-2026-46476","title":"CVE-2026-46476: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2…","headline":"Flowise mass-assignment flaw enables cross-workspace template takeover","severity":"high","publishedAt":"2026-06-08T16:16:41.950Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":0.00561,"matchedBy":"ecosystem"},{"id":"b3447ff6-40dd-486a-ae70-55c774e3c43c","url":"https://aisecwatch.com/issues/b3447ff6-40dd-486a-ae70-55c774e3c43c","cveId":"CVE-2026-46475","title":"CVE-2026-46475: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2…","headline":"Flowise assistant mass-assignment allows cross-workspace takeover","severity":"high","publishedAt":"2026-06-08T16:16:41.810Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":0.00561,"matchedBy":"ecosystem"},{"id":"f1c75c9f-ceef-48f7-9aeb-d4c868e194d6","url":"https://aisecwatch.com/issues/f1c75c9f-ceef-48f7-9aeb-d4c868e194d6","cveId":"CVE-2026-46444","title":"CVE-2026-46444: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all…","headline":"Flowise OpenAI Assistants Vector Store endpoints lack authentication","severity":"high","publishedAt":"2026-06-08T16:16:41.660Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":0.00555,"matchedBy":"ecosystem"},{"id":"44d671b1-820f-433d-a355-7223bac2ddb4","url":"https://aisecwatch.com/issues/44d671b1-820f-433d-a355-7223bac2ddb4","cveId":"CVE-2026-46443","title":"CVE-2026-46443: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when…","headline":"Flowise credential retrieval exposes encrypted data via credentialName filter","severity":"high","publishedAt":"2026-06-08T16:16:41.493Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":0.00369,"matchedBy":"ecosystem"},{"id":"165139e4-2768-4eca-b45d-d9b86eba28d7","url":"https://aisecwatch.com/issues/165139e4-2768-4eca-b45d-d9b86eba28d7","cveId":"CVE-2026-46442","title":"CVE-2026-46442: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST…","headline":"Flowise remote code execution through /api/v1/node-custom-function endpoint","severity":"critical","publishedAt":"2026-06-08T16:16:41.347Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":0.03414,"matchedBy":"ecosystem"},{"id":"a912bfce-4f66-4d03-85cd-f803357f4cf7","url":"https://aisecwatch.com/issues/a912bfce-4f66-4d03-85cd-f803357f4cf7","cveId":"CVE-2026-46441","title":"CVE-2026-46441: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass…","headline":"Flowise mass assignment in assistant update endpoint allows workspace","severity":"medium","publishedAt":"2026-06-08T16:16:41.190Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":0.00367,"matchedBy":"ecosystem"},{"id":"01683808-a19f-4201-92e4-ecad7e3a61a4","url":"https://aisecwatch.com/issues/01683808-a19f-4201-92e4-ecad7e3a61a4","cveId":"CVE-2026-46440","title":"CVE-2026-46440: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the…","headline":"Flowise checkBasicAuth validates plaintext creds without rate limiting","severity":"high","publishedAt":"2026-06-08T16:16:41.043Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":0.00422,"matchedBy":"ecosystem"},{"id":"bddf003b-1c90-4436-a94b-ef7bcbde9b2a","url":"https://aisecwatch.com/issues/bddf003b-1c90-4436-a94b-ef7bcbde9b2a","cveId":null,"title":"GHSA-c2c9-mfw7-p8hw: Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows","headline":null,"severity":"medium","publishedAt":"2026-05-20T15:45:19.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"741bdf3f-703c-4185-806c-07bc15bcd97c","url":"https://aisecwatch.com/issues/741bdf3f-703c-4185-806c-07bc15bcd97c","cveId":null,"title":"GHSA-59fh-9f3p-7m39: Flowise: Mass Assignment in PUT /api/v1/user Allows Authenticated Users to Override Password Hash and Bypass Password Change Verification","headline":null,"severity":"medium","publishedAt":"2026-05-20T15:44:40.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"bc15ff43-c7de-4ada-a9bc-644a250bd0da","url":"https://aisecwatch.com/issues/bc15ff43-c7de-4ada-a9bc-644a250bd0da","cveId":null,"title":"GHSA-m837-xvxr-vqwg: Flowise: Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpage","headline":null,"severity":"medium","publishedAt":"2026-05-20T15:38:02.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"0dfdb2f7-bfaa-482b-9442-be781d599e58","url":"https://aisecwatch.com/issues/0dfdb2f7-bfaa-482b-9442-be781d599e58","cveId":null,"title":"GHSA-wxrr-jp8m-qq7f: FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover","headline":null,"severity":"high","publishedAt":"2026-05-14T16:19:52.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"12f42caa-8508-447d-822a-17138d2b717e","url":"https://aisecwatch.com/issues/12f42caa-8508-447d-822a-17138d2b717e","cveId":null,"title":"GHSA-mq53-pc65-wjc4: FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover","headline":null,"severity":"high","publishedAt":"2026-05-14T16:19:49.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"c11b7394-011a-404e-a063-7a79d303e0be","url":"https://aisecwatch.com/issues/c11b7394-011a-404e-a063-7a79d303e0be","cveId":null,"title":"GHSA-7j65-65cr-6644: FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover","headline":null,"severity":"high","publishedAt":"2026-05-14T16:19:44.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"9daf4ecc-05e6-4f2b-9b37-7c390f274f3e","url":"https://aisecwatch.com/issues/9daf4ecc-05e6-4f2b-9b37-7c390f274f3e","cveId":null,"title":"GHSA-5h9v-837x-m97r: FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover","headline":null,"severity":"high","publishedAt":"2026-05-14T16:19:39.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"1c2202eb-b54c-46f6-a949-106247825b21","url":"https://aisecwatch.com/issues/1c2202eb-b54c-46f6-a949-106247825b21","cveId":null,"title":"GHSA-728h-4mwj-f2p4: FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover","headline":null,"severity":"high","publishedAt":"2026-05-14T16:19:32.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"b13245fc-89ea-4b8b-af2c-43c150f5c74b","url":"https://aisecwatch.com/issues/b13245fc-89ea-4b8b-af2c-43c150f5c74b","cveId":null,"title":"GHSA-78pr-c5x5-jggc: FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover","headline":null,"severity":"high","publishedAt":"2026-05-14T16:19:28.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"cc9b1207-e32e-4ed0-831d-e21039c344f2","url":"https://aisecwatch.com/issues/cc9b1207-e32e-4ed0-831d-e21039c344f2","cveId":null,"title":"GHSA-hmg2-jjjx-jcp2: FlowiseAI: Vector Store No Permission Checks","headline":null,"severity":"high","publishedAt":"2026-05-14T16:19:23.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"f5d04c5b-05f3-4dc4-bb97-061f6ad9d5a3","url":"https://aisecwatch.com/issues/f5d04c5b-05f3-4dc4-bb97-061f6ad9d5a3","cveId":null,"title":"GHSA-7g73-99r4-m4mj: FlowiseAI Vulnerable to Credential Data Leak","headline":null,"severity":"high","publishedAt":"2026-05-14T14:58:12.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"95cf2bec-b389-4908-80fa-2cd352ddf5f1","url":"https://aisecwatch.com/issues/95cf2bec-b389-4908-80fa-2cd352ddf5f1","cveId":null,"title":"GHSA-9rvc-vf7m-pgm2: FlowiseAI: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape","headline":null,"severity":"critical","publishedAt":"2026-05-14T14:57:53.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"f2321133-2c3c-43af-bd42-f189f087642d","url":"https://aisecwatch.com/issues/f2321133-2c3c-43af-bd42-f189f087642d","cveId":null,"title":"GHSA-hp26-q66v-q2w7: FlowiseAI has Mass Assignment in Assistant Update Endpoint that Allows Cross-Workspace Resource Reassignment","headline":null,"severity":"high","publishedAt":"2026-05-14T14:57:46.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"185696db-2282-4cc5-baf2-7e55eb9d51be","url":"https://aisecwatch.com/issues/185696db-2282-4cc5-baf2-7e55eb9d51be","cveId":null,"title":"GHSA-m99r-2hxc-cp3q: Flowise has an MCP Security Bypass that Enables RCE","headline":null,"severity":"high","publishedAt":"2026-05-14T14:57:30.000Z","affected":["flowise-components@<= 3.1.1 (fixed: 3.1.2)","flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"9dcb39c2-f4cc-4724-86a6-8127f693abbc","url":"https://aisecwatch.com/issues/9dcb39c2-f4cc-4724-86a6-8127f693abbc","cveId":null,"title":"GHSA-php6-83fg-gw3g: FlowiseAI Exposes Basic Auth Credentials via API","headline":null,"severity":"high","publishedAt":"2026-05-14T14:54:46.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"1428e37e-595b-4b01-bbc2-1a3c38933eb8","url":"https://aisecwatch.com/issues/1428e37e-595b-4b01-bbc2-1a3c38933eb8","cveId":"CVE-2026-42863","title":"GHSA-5wxp-qjgq-fx6m: FlowiseAI has Mass Assignment in Chatflow Update Endpoint that Allows Cross-Workspace AgentFlow Reassignment","headline":null,"severity":"high","publishedAt":"2026-05-14T14:54:28.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":0.00367,"matchedBy":"ecosystem"},{"id":"7ec2757e-6f45-4338-ac7d-2cbaa5146eb5","url":"https://aisecwatch.com/issues/7ec2757e-6f45-4338-ac7d-2cbaa5146eb5","cveId":"CVE-2026-42862","title":"GHSA-x5v6-pj28-cwwm: FlowiseAI has Mass Assignment in Tool Update Endpoint that Allows Cross-Workspace Resource Reassignment","headline":null,"severity":"high","publishedAt":"2026-05-14T14:52:40.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":0.00275,"matchedBy":"ecosystem"},{"id":"44403932-937b-4a55-aee9-3e7628aa478b","url":"https://aisecwatch.com/issues/44403932-937b-4a55-aee9-3e7628aa478b","cveId":"CVE-2026-42861","title":"GHSA-6fw7-3q8r-m5vj: FlowiseAI has Mass Assignment in Variable Update Endpoint that Allows Cross-Workspace Resource Reassignment","headline":null,"severity":"high","publishedAt":"2026-05-14T14:52:24.000Z","affected":["flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":0.00367,"matchedBy":"ecosystem"},{"id":"4e0bd950-f01e-4da1-8032-a2df8c7678c7","url":"https://aisecwatch.com/issues/4e0bd950-f01e-4da1-8032-a2df8c7678c7","cveId":"CVE-2026-43995","title":"CVE-2026-43995: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool…","headline":"Flowise tools bypass secured wrapper and invoke raw HTTP clients","severity":"medium","publishedAt":"2026-05-11T18:16:37.660Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00484,"matchedBy":"ecosystem"},{"id":"db5616eb-c907-46b3-93fe-9f055704457e","url":"https://aisecwatch.com/issues/db5616eb-c907-46b3-93fe-9f055704457e","cveId":"CVE-2026-41274","title":"CVE-2026-41274: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the…","headline":"Flowise GraphCypherQAChain node Cypher injection into Neo4j database","severity":"critical","publishedAt":"2026-04-23T22:16:38.740Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00735,"matchedBy":"ecosystem"},{"id":"5790f1e8-11eb-4dc5-938f-98ffc6074b2d","url":"https://aisecwatch.com/issues/5790f1e8-11eb-4dc5-938f-98ffc6074b2d","cveId":"CVE-2026-41279","title":"CVE-2026-41279: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the…","headline":"Flowise unauthenticated text-to-speech endpoint exposes stored API credentials","severity":"high","publishedAt":"2026-04-23T20:16:16.687Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00396,"matchedBy":"ecosystem"},{"id":"c895b4df-7bd8-46b3-ba8e-5b2ae23a66e3","url":"https://aisecwatch.com/issues/c895b4df-7bd8-46b3-ba8e-5b2ae23a66e3","cveId":"CVE-2026-41278","title":"CVE-2026-41278: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET…","headline":"Flowise public chatflow endpoint exposes unsanitized chatflow data","severity":"high","publishedAt":"2026-04-23T20:16:16.550Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00429,"matchedBy":"ecosystem"},{"id":"56e6e14c-12d2-4719-b0f1-a241e17a1a6a","url":"https://aisecwatch.com/issues/56e6e14c-12d2-4719-b0f1-a241e17a1a6a","cveId":"CVE-2026-41277","title":"CVE-2026-41277: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass…","headline":"Flowise mass assignment in DocumentStore endpoint allows overwriting objects","severity":"high","publishedAt":"2026-04-23T20:16:16.410Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00476,"matchedBy":"ecosystem"},{"id":"17bd547a-3fab-4d65-9d19-272c349692ee","url":"https://aisecwatch.com/issues/17bd547a-3fab-4d65-9d19-272c349692ee","cveId":"CVE-2026-41276","title":"CVE-2026-41276: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this…","headline":"Flowise authentication bypass in password reset","severity":"critical","publishedAt":"2026-04-23T20:16:16.270Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00648,"matchedBy":"ecosystem"},{"id":"18dc342d-a32c-4275-a8bb-13e9a0a2e14d","url":"https://aisecwatch.com/issues/18dc342d-a32c-4275-a8bb-13e9a0a2e14d","cveId":"CVE-2026-41275","title":"CVE-2026-41275: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password…","headline":"Flowise password reset sends reset link over unsecured HTTP","severity":"medium","publishedAt":"2026-04-23T20:16:16.117Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00252,"matchedBy":"ecosystem"},{"id":"acd4bb83-9090-461b-bcad-9b84d76dd0de","url":"https://aisecwatch.com/issues/acd4bb83-9090-461b-bcad-9b84d76dd0de","cveId":"CVE-2026-41273","title":"CVE-2026-41273: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise…","headline":"Flowise authentication bypass exposing OAuth tokens","severity":"high","publishedAt":"2026-04-23T20:16:15.973Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00444,"matchedBy":"ecosystem"},{"id":"bd022616-d025-431d-9cd3-b398718546a9","url":"https://aisecwatch.com/issues/bd022616-d025-431d-9cd3-b398718546a9","cveId":"CVE-2026-41272","title":"CVE-2026-41272: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core…","headline":"Flowise SSRF protection bypass via DNS rebinding and default configuration","severity":"high","publishedAt":"2026-04-23T20:16:15.810Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00354,"matchedBy":"ecosystem"},{"id":"9e77eaca-1304-493f-ba38-cedd8b70aec7","url":"https://aisecwatch.com/issues/9e77eaca-1304-493f-ba38-cedd8b70aec7","cveId":"CVE-2026-41271","title":"CVE-2026-41271: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side…","headline":"Flowise server-side request forgery in POST/GET API Chain components","severity":"high","publishedAt":"2026-04-23T20:16:15.683Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00342,"matchedBy":"ecosystem"},{"id":"3f5b8e7a-9823-44c0-960d-71bf00127372","url":"https://aisecwatch.com/issues/3f5b8e7a-9823-44c0-960d-71bf00127372","cveId":"CVE-2026-41270","title":"CVE-2026-41270: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side…","headline":"Flowise SSRF protection bypass in Custom Function feature","severity":"high","publishedAt":"2026-04-23T20:16:15.547Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00332,"matchedBy":"ecosystem"},{"id":"3e34ee2f-18e8-470a-aa19-70f5025fdf09","url":"https://aisecwatch.com/issues/3e34ee2f-18e8-470a-aa19-70f5025fdf09","cveId":"CVE-2026-41269","title":"CVE-2026-41269: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow…","headline":"Flowise arbitrary JavaScript upload through Chatflow file upload settings","severity":"high","publishedAt":"2026-04-23T20:16:15.417Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00692,"matchedBy":"ecosystem"},{"id":"9e1452d8-5767-420e-a4ba-bb2e23b01072","url":"https://aisecwatch.com/issues/9e1452d8-5767-420e-a4ba-bb2e23b01072","cveId":"CVE-2026-41268","title":"CVE-2026-41268: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is…","headline":"Flowise unauthenticated remote command execution via parameter override bypass","severity":"critical","publishedAt":"2026-04-23T20:16:15.300Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.01247,"matchedBy":"ecosystem"},{"id":"18cb661f-79e5-445f-9be9-d1ba6931caa0","url":"https://aisecwatch.com/issues/18cb661f-79e5-445f-9be9-d1ba6931caa0","cveId":"CVE-2026-41267","title":"CVE-2026-41267: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper…","headline":"Flowise mass assignment in account registration endpoint of Flowise Cloud","severity":"high","publishedAt":"2026-04-23T20:16:15.160Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00483,"matchedBy":"ecosystem"},{"id":"c50cf22f-1fc9-4386-818b-0835b3437b87","url":"https://aisecwatch.com/issues/c50cf22f-1fc9-4386-818b-0835b3437b87","cveId":"CVE-2026-41266","title":"CVE-2026-41266: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0…","headline":"Flowise exposure of sensitive data through /api/v1/public-chatbotConfig/:id","severity":"high","publishedAt":"2026-04-23T20:16:15.030Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00501,"matchedBy":"ecosystem"},{"id":"d9688a7f-f181-43d3-a9d8-4aa865d516bf","url":"https://aisecwatch.com/issues/d9688a7f-f181-43d3-a9d8-4aa865d516bf","cveId":"CVE-2026-41265","title":"CVE-2026-41265: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific…","headline":"Flowise command execution via prompt injection in Airtable Agent node","severity":"critical","publishedAt":"2026-04-23T20:16:14.890Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00555,"matchedBy":"ecosystem"},{"id":"fa4bef48-e49c-43f4-888c-2527a9bff35a","url":"https://aisecwatch.com/issues/fa4bef48-e49c-43f4-888c-2527a9bff35a","cveId":"CVE-2026-41138","title":"CVE-2026-41138: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a…","headline":"Flowise remote code execution through AirtableAgent Pandas prompt input","severity":"critical","publishedAt":"2026-04-23T20:16:14.380Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00845,"matchedBy":"ecosystem"},{"id":"1641cc73-d00b-40ea-8d12-90ddd00d4339","url":"https://aisecwatch.com/issues/1641cc73-d00b-40ea-8d12-90ddd00d4339","cveId":"CVE-2026-41137","title":"CVE-2026-41137: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent…","headline":"Flowise command injection through CSVAgent custom Pandas CSV read code","severity":"critical","publishedAt":"2026-04-23T20:16:14.257Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.02051,"matchedBy":"ecosystem"},{"id":"e2f0ed54-f2bf-4959-bc2b-50193b6e54ce","url":"https://aisecwatch.com/issues/e2f0ed54-f2bf-4959-bc2b-50193b6e54ce","cveId":"CVE-2026-40933","title":"CVE-2026-40933: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe…","headline":"Flowise command execution through Custom MCP stdio server configuration","severity":"critical","publishedAt":"2026-04-21T22:16:19.383Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.01283,"matchedBy":"ecosystem"},{"id":"68e23887-4c48-4a58-acfb-59322d06e9c2","url":"https://aisecwatch.com/issues/68e23887-4c48-4a58-acfb-59322d06e9c2","cveId":"CVE-2026-41264","title":"GHSA-3hjv-c53m-58jj: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability","headline":null,"severity":"critical","publishedAt":"2026-04-21T20:19:52.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.01165,"matchedBy":"ecosystem"},{"id":"507e419d-a9f0-488b-8218-047e9fc1f88f","url":"https://aisecwatch.com/issues/507e419d-a9f0-488b-8218-047e9fc1f88f","cveId":null,"title":"GHSA-v38x-c887-992f: Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability","headline":null,"severity":"critical","publishedAt":"2026-04-18T00:46:04.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"96135911-abf6-4c15-98f2-d82145a46e6f","url":"https://aisecwatch.com/issues/96135911-abf6-4c15-98f2-d82145a46e6f","cveId":null,"title":"GHSA-5fw2-mwhh-9947: Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials","headline":null,"severity":"high","publishedAt":"2026-04-17T21:35:14.000Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"b49665fa-8df0-4231-aca3-38a74f240354","url":"https://aisecwatch.com/issues/b49665fa-8df0-4231-aca3-38a74f240354","cveId":null,"title":"GHSA-w47f-j8rh-wx87: Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs","headline":null,"severity":"high","publishedAt":"2026-04-17T21:34:30.000Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"dcad266b-47f3-4060-b8f6-ad1e205b4a44","url":"https://aisecwatch.com/issues/dcad266b-47f3-4060-b8f6-ad1e205b4a44","cveId":null,"title":"GHSA-f6hc-c5jr-878p: Flowise: resetPassword Authentication Bypass Vulnerability","headline":null,"severity":"high","publishedAt":"2026-04-16T21:55:18.000Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"437a194c-be91-49be-a2cf-1e36f2e8286b","url":"https://aisecwatch.com/issues/437a194c-be91-49be-a2cf-1e36f2e8286b","cveId":null,"title":"GHSA-28g4-38q8-3cwc: Flowise: Cypher Injection in GraphCypherQAChain","headline":null,"severity":"high","publishedAt":"2026-04-16T21:54:26.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"135f10b4-833a-40eb-b8f1-4a5e9078cadd","url":"https://aisecwatch.com/issues/135f10b4-833a-40eb-b8f1-4a5e9078cadd","cveId":null,"title":"GHSA-x5w6-38gp-mrqh: Flowise: Password Reset Link Sent Over Unsecured HTTP","headline":null,"severity":"high","publishedAt":"2026-04-16T21:53:16.000Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"75abb0fa-b865-458c-808f-ba50c517fbfe","url":"https://aisecwatch.com/issues/75abb0fa-b865-458c-808f-ba50c517fbfe","cveId":null,"title":"GHSA-6f7g-v4pp-r667: Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow in Flowise","headline":null,"severity":"high","publishedAt":"2026-04-16T21:52:46.000Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"3661703c-5c7c-4dc2-bddd-b9116db46ff4","url":"https://aisecwatch.com/issues/3661703c-5c7c-4dc2-bddd-b9116db46ff4","cveId":null,"title":"GHSA-6r77-hqx7-7vw8: Flowise:  APIChain Prompt Injection SSRF in GET/POST API Chains","headline":null,"severity":"high","publishedAt":"2026-04-16T21:52:11.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"1c85c082-06d4-4aa2-a39c-f1f0e10425a6","url":"https://aisecwatch.com/issues/1c85c082-06d4-4aa2-a39c-f1f0e10425a6","cveId":null,"title":"GHSA-2x8m-83vc-6wv4: Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)","headline":null,"severity":"high","publishedAt":"2026-04-16T21:51:00.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"7e7b6962-c0dc-4015-b091-42c85f2c6c50","url":"https://aisecwatch.com/issues/7e7b6962-c0dc-4015-b091-42c85f2c6c50","cveId":null,"title":"GHSA-xhmj-rg95-44hv: Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox","headline":null,"severity":"high","publishedAt":"2026-04-16T21:50:12.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"7866b0d0-f437-4549-89d9-8f6685452a43","url":"https://aisecwatch.com/issues/7866b0d0-f437-4549-89d9-8f6685452a43","cveId":null,"title":"GHSA-rh7v-6w34-w2rr: Flowise: File Upload Validation Bypass in createAttachment","headline":null,"severity":"high","publishedAt":"2026-04-16T21:49:28.000Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"998fddfa-3b4a-439e-9f4a-2ec3e703417b","url":"https://aisecwatch.com/issues/998fddfa-3b4a-439e-9f4a-2ec3e703417b","cveId":null,"title":"GHSA-cvrr-qhgw-2mm6: Flowise: Parameter Override Bypass Remote Command Execution","headline":null,"severity":"high","publishedAt":"2026-04-16T21:46:39.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"0633adfc-bdf6-4cf6-99eb-7d74d7b4884e","url":"https://aisecwatch.com/issues/0633adfc-bdf6-4cf6-99eb-7d74d7b4884e","cveId":null,"title":"GHSA-4jpm-cgx2-8h37: Flowise: Sensitive Data Leak in public-chatbotConfig ","headline":null,"severity":"high","publishedAt":"2026-04-16T21:44:49.000Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"02a13b75-ec08-4a7a-a886-7c0e5dd574e4","url":"https://aisecwatch.com/issues/02a13b75-ec08-4a7a-a886-7c0e5dd574e4","cveId":null,"title":"GHSA-48m6-ch88-55mj: Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association","headline":null,"severity":"high","publishedAt":"2026-04-16T21:44:24.000Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"58bd513d-fa76-4a5d-bbb0-c948e6a1cf14","url":"https://aisecwatch.com/issues/58bd513d-fa76-4a5d-bbb0-c948e6a1cf14","cveId":null,"title":"GHSA-9wc7-mj3f-74xv: Flowise: Code Injection in CSVAgent leads to Authenticated RCE","headline":null,"severity":"critical","publishedAt":"2026-04-16T21:44:15.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"7f2cdab6-751d-4130-a1f3-1e7e6a94dcf4","url":"https://aisecwatch.com/issues/7f2cdab6-751d-4130-a1f3-1e7e6a94dcf4","cveId":null,"title":"GHSA-f228-chmx-v6j6: Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.","headline":null,"severity":"high","publishedAt":"2026-04-16T21:43:57.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"8d91908b-5f36-4e29-8d09-121cedada4f8","url":"https://aisecwatch.com/issues/8d91908b-5f36-4e29-8d09-121cedada4f8","cveId":"CVE-2026-31829","title":"CVE-2026-31829: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise…","headline":"Flowise SSRF through HTTP Node in AgentFlow and Chatflow","severity":"high","publishedAt":"2026-03-10T22:16:20.937Z","affected":["flowise@<= 3.0.12 (fixed: 3.0.13)","flowise-components@<= 3.0.12 (fixed: 3.0.13)"],"epssScore":0.00391,"matchedBy":"ecosystem"},{"id":"152eb38c-4b41-49aa-9f41-791699855ee9","url":"https://aisecwatch.com/issues/152eb38c-4b41-49aa-9f41-791699855ee9","cveId":"CVE-2026-30824","title":"GHSA-5f53-522j-j454: Flowise Missing Authentication on NVIDIA NIM Endpoints","headline":null,"severity":"high","publishedAt":"2026-03-06T22:21:38.000Z","affected":["flowise@<= 3.0.12 (fixed: 3.0.13)"],"epssScore":0.02638,"matchedBy":"ecosystem"},{"id":"ddf259b7-4131-420e-ac62-17a7749c5b09","url":"https://aisecwatch.com/issues/ddf259b7-4131-420e-ac62-17a7749c5b09","cveId":"CVE-2026-30823","title":"GHSA-cwc3-p92j-g7qm: Flowise has IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration","headline":null,"severity":"high","publishedAt":"2026-03-06T22:20:50.000Z","affected":["flowise@<= 3.0.12 (fixed: 3.0.13)"],"epssScore":0.00492,"matchedBy":"ecosystem"},{"id":"2d3ded6d-e2a4-4008-89e1-5f5a3ce26157","url":"https://aisecwatch.com/issues/2d3ded6d-e2a4-4008-89e1-5f5a3ce26157","cveId":"CVE-2026-30822","title":"GHSA-mq4r-h2gh-qv7x: Flowise Allows Mass Assignment in `/api/v1/leads` Endpoint","headline":null,"severity":"high","publishedAt":"2026-03-06T22:19:14.000Z","affected":["flowise@<= 3.0.12 (fixed: 3.0.13)"],"epssScore":0.00512,"matchedBy":"ecosystem"},{"id":"52df124b-2cb9-456c-b1c8-6d78be4e3889","url":"https://aisecwatch.com/issues/52df124b-2cb9-456c-b1c8-6d78be4e3889","cveId":"CVE-2026-30821","title":"GHSA-j8g8-j7fc-43v6: Flowise has Arbitrary File Upload via MIME Spoofing","headline":null,"severity":"high","publishedAt":"2026-03-06T18:49:20.000Z","affected":["flowise@<= 3.0.12 (fixed: 3.0.13)"],"epssScore":0.00933,"matchedBy":"ecosystem"},{"id":"4ca134fa-55ca-4e7f-b88f-27360910f5de","url":"https://aisecwatch.com/issues/4ca134fa-55ca-4e7f-b88f-27360910f5de","cveId":"CVE-2026-30820","title":"GHSA-wvhq-wp8g-c7vq: Flowise has Authorization Bypass via Spoofed x-request-from Header","headline":null,"severity":"high","publishedAt":"2026-03-06T18:48:22.000Z","affected":["flowise@<= 3.0.12 (fixed: 3.0.13)"],"epssScore":0.00646,"matchedBy":"ecosystem"},{"id":"a67a4700-c745-455a-8100-bcf5551d861f","url":"https://aisecwatch.com/issues/a67a4700-c745-455a-8100-bcf5551d861f","cveId":null,"title":"GHSA-jc5m-wrp2-qq38: Flowise Vulnerable to PII Disclosure on Unauthenticated Forgot Password Endpoint","headline":null,"severity":"medium","publishedAt":"2026-03-05T21:58:02.000Z","affected":["flowise@<= 3.0.12 (fixed: 3.0.13)"],"epssScore":null,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:52:28.322Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}