| CVE-2026-73483GHSA-9gvv-qjj3-2p6g: Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via Chromium | Critical | <= 3.1.2 | 3.1.3 | 2026-10-07 |
| CVE-2026-73487CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows… | Critical | <= 3.1.2 | 3.1.3 | 2026-08-13 |
| CVE-2026-70478GHSA-qgvm-j2hm-6m38: Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service | Critical | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-70477GHSA-5xvg-pmgg-3mxr: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability | Critical | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-70476GHSA-gmmw-qg98-6j6p: Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation | High | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| GHSA-8gj2-2cvc-6xx7: Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials | Medium | <= 3.1.3 | 3.1.4 | 2026-08-04 |
| CVE-2026-70475GHSA-fm2f-4339-4p2f: Flowise: Missing Authorization on Execution Update Endpoint | High | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-70474GHSA-wch5-xp77-fxg4: Flowise: Cross-Workspace OAuth2 Credential Metadata Leak | High | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| GHSA-rwrp-9823-p2xq: Flowise: Incomplete Credential Redaction Exposes Secrets via API | Medium | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-70473GHSA-fr6g-7cq8-fg82: Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history | High | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-70472GHSA-chm3-vqcf-52rx: Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store | High | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-69264GHSA-4j8x-x6v7-w9rq: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation | Critical | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| GHSA-88pr-878c-24wf: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys | High | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-70471GHSA-8r8h-6vcc-xhrv: Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure | High | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-70470GHSA-52fh-8v99-63c2: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE | Critical | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-69263GHSA-xc48-889x-5qmw: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE) | High | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-69262GHSA-p5w8-m249-4r4v: Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type | High | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-69259GHSA-x3hf-7cj6-3r4m: Flowise RCE via SQLite Record Manager Node | Critical | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-69258GHSA-6vh2-wg4h-4vwj: Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API | High | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-69257GHSA-c6xh-wv4j-ppv5: Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses | High | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-69256GHSA-x6vm-w76m-8j7g: Flowise: Remote Code Execution Vulnerability in CSVAgent | Critical | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-69255GHSA-vmv7-4m6c-3cg5: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified | Critical | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-69254GHSA-3769-jgqc-cxm7: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override | Critical | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-69253GHSA-wg86-r78f-74mp: Flowise Sandbox Escape to RCE | Critical | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-69252GHSA-wp74-f5hh-5f3r: Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization | High | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-69251GHSA-g32j-mmxr-gfq5: Flowise RCE via TypeORM DataSource | Critical | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-69250GHSA-r745-8hwv-h473: Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration | High | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| GHSA-2364-jh4q-m9vm: Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint | Medium | <= 3.1.2 | 3.1.3 | 2026-08-04 |
| CVE-2026-46480CVE-2026-46480: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2… | High | <= 3.1.1 | 3.1.2 | 2026-06-08 |
| CVE-2026-46479CVE-2026-46479: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2… | High | <= 3.1.1 | 3.1.2 | 2026-06-08 |
| CVE-2026-46478CVE-2026-46478: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2… | High | <= 3.1.1 | 3.1.2 | 2026-06-08 |
| CVE-2026-46477CVE-2026-46477: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2… | High | <= 3.1.1 | 3.1.2 | 2026-06-08 |
| CVE-2026-46476CVE-2026-46476: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2… | High | <= 3.1.1 | 3.1.2 | 2026-06-08 |
| CVE-2026-46475CVE-2026-46475: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2… | High | <= 3.1.1 | 3.1.2 | 2026-06-08 |
| CVE-2026-46444CVE-2026-46444: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all… | High | <= 3.1.1 | 3.1.2 | 2026-06-08 |
| CVE-2026-46443CVE-2026-46443: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when… | High | <= 3.1.1 | 3.1.2 | 2026-06-08 |
| CVE-2026-46442CVE-2026-46442: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST… | Critical | <= 3.1.1 | 3.1.2 | 2026-06-08 |
| CVE-2026-46441CVE-2026-46441: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass… | Medium | <= 3.1.1 | 3.1.2 | 2026-06-08 |
| CVE-2026-46440CVE-2026-46440: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the… | High | <= 3.1.1 | 3.1.2 | 2026-06-08 |
| GHSA-c2c9-mfw7-p8hw: Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows | Medium | <= 3.1.1 | 3.1.2 | 2026-05-20 |
| GHSA-59fh-9f3p-7m39: Flowise: Mass Assignment in PUT /api/v1/user Allows Authenticated Users to Override Password Hash and Bypass Password Change Verification | Medium | <= 3.1.1 | 3.1.2 | 2026-05-20 |
| GHSA-m837-xvxr-vqwg: Flowise: Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpage | Medium | <= 3.1.1 | 3.1.2 | 2026-05-20 |
| GHSA-wxrr-jp8m-qq7f: FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover | High | <= 3.1.1 | 3.1.2 | 2026-05-14 |
| GHSA-mq53-pc65-wjc4: FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover | High | <= 3.1.1 | 3.1.2 | 2026-05-14 |
| GHSA-7j65-65cr-6644: FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover | High | <= 3.1.1 | 3.1.2 | 2026-05-14 |
| GHSA-5h9v-837x-m97r: FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover | High | <= 3.1.1 | 3.1.2 | 2026-05-14 |
| GHSA-728h-4mwj-f2p4: FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover | High | <= 3.1.1 | 3.1.2 | 2026-05-14 |
| GHSA-78pr-c5x5-jggc: FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover | High | <= 3.1.1 | 3.1.2 | 2026-05-14 |
| GHSA-hmg2-jjjx-jcp2: FlowiseAI: Vector Store No Permission Checks | High | <= 3.1.1 | 3.1.2 | 2026-05-14 |
| GHSA-7g73-99r4-m4mj: FlowiseAI Vulnerable to Credential Data Leak | High | <= 3.1.1 | 3.1.2 | 2026-05-14 |