flowise vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-70478Criticalflowise: Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected serviceCVE-2026-70477Criticalflowise: Flowise: CSV Agent Prompt Injection Remote Code Execution VulnerabilityCVE-2026-70476Highflowise: Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing ManipulationGHSA-8GJ2-2CVC-6XX7Mediumflowise: Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS CredentialsCVE-2026-70475Highflowise: Flowise: Missing Authorization on Execution Update EndpointCVE-2026-70474Highflowise: Flowise: Cross-Workspace OAuth2 Credential Metadata LeakGHSA-RWRP-9823-P2XQMediumflowise: Flowise: Incomplete Credential Redaction Exposes Secrets via APICVE-2026-70473Highflowise: Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert historyCVE-2026-70472Highflowise: Flowise: Cross-workspace credential IDOR in openai-assistants-vector-storeCVE-2026-69264Criticalflowise: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validationGHSA-88PR-878C-24WFHighflowise-components: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys …CVE-2026-70471Highflowise: Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables DisclosureCVE-2026-70470Criticalflowise: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCECVE-2026-69263Highflowise: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)CVE-2026-69262Highflowise: Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each…CVE-2026-69259Criticalflowise: Flowise RCE via SQLite Record Manager NodeCVE-2026-69258Highflowise: Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction APICVE-2026-69257Highflowise: Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 AddressesCVE-2026-69256Criticalflowise-components: Flowise: Remote Code Execution Vulnerability in CSVAgentCVE-2026-69255Criticalflowise: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell VerifiedCVE-2026-69254Criticalflowise: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions OverrideCVE-2026-69253Criticalflowise: Flowise Sandbox Escape to RCECVE-2026-69252Highflowise: Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same…CVE-2026-69251Criticalflowise: Flowise RCE via TypeORM DataSourceCVE-2026-69250Highflowise: Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration

Stop the waste.
Protect your environment with Kodem.