flowiseai security advisories
13 threat alerts tracking vulnerabilities and security advisories that affect flowiseai products.
Vulnios monitors flowiseai CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent flowiseai security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2025-34267 — flowiseai — flowise
Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated
criticalCVE-2025-34267Critical Vulnerability: CVE-2025-71333 — flowiseai — flowise
Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the
criticalCVE-2025-71333Critical Vulnerability: CVE-2026-42861 — flowiseai — flowise
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the variable update endpoint of FlowiseAI. Th
criticalCVE-2026-42861Critical Vulnerability: CVE-2026-46440 — flowiseai — flowise
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting an
criticalCVE-2026-46440Critical Vulnerability: CVE-2026-46441 — flowiseai — flowise
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. T
criticalCVE-2026-46441Critical Vulnerability: CVE-2026-46442 — flowiseai — flowise
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authent
criticalCVE-2026-46442Critical Vulnerability: CVE-2026-43995 — flowiseai — flowise
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool implementations directly import and invoke raw HTTP clients (node-fetch, axios) i
criticalCVE-2026-43995Critical Vulnerability: CVE-2026-41274 — flowiseai — flowise
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-provided input directly into the Cypher query executi
criticalCVE-2026-41274Critical Vulnerability: CVE-2026-41265 — flowiseai — flowise
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the Airtable_Agents class. The issue results
criticalCVE-2026-41265Critical Vulnerability: CVE-2026-41268 — flowiseai — flowise
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthenticated remote command execution (RCE) vulnerabilit
criticalCVE-2026-41268Critical Vulnerability: CVE-2026-41276 — flowiseai — flowise
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass authentication on affected installations o
criticalCVE-2026-41276Critical Vulnerability: CVE-2026-41264 — flowiseai — flowise
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the CSV_Agents class. The issue results from
criticalCVE-2026-41264Critical Vulnerability: CVE-2026-40933 — flowiseai — flowise
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can
criticalCVE-2026-40933
Track flowiseai exposure across your environment
Vulnios automatically cross-references your asset inventory against new flowiseai CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan