Flowise Vulnerabilities

npm AI Agents

AI Threat Alert tracks 159 known vulnerabilities in Flowise, 36 rated critical — an AI/ML ai agents in the npm ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
159
Total CVEs
36
Critical
npm
Ecosystem
Aug 13, 2026
Last CVE
50%
Patch Rate
2d
Avg Time to Patch

Known Vulnerabilities (159 total, page 1 of 7)

Severity CVE ID Summary CVSS Published
MEDIUM CVE-2026-73604 Flowise: API leaks decrypted credentials in plaintext 6.5 Aug 13, 2026 MEDIUM CVE-2026-73603 Flowise: unauth TTS endpoint drains stored API keys -- Aug 13, 2026 CRITICAL CVE-2026-73487 Flowise: Python sandbox bypass enables unauth RCE -- Aug 13, 2026 UNKNOWN CVE-2026-73486 Flowise: CSV Agent code injection enables RCE -- Aug 13, 2026 CRITICAL CVE-2026-73601 Flowise: RCE via Custom MCP node env var injection -- Aug 13, 2026 UNKNOWN CVE-2026-73488 Flowise: IDOR exposes cross-tenant billing/PII data -- Aug 13, 2026 UNKNOWN CVE-2026-73602 Flowise: vm2 sandbox escape enables RCE -- Aug 13, 2026 CRITICAL CVE-2026-73483 Flowise: sandbox escape via puppeteer.launch() to RCE -- Aug 13, 2026 UNKNOWN CVE-2026-73484 Flowise: Pandas sandbox bypass leaks files, writes to disk -- Aug 13, 2026 CRITICAL CVE-2026-73485 Flowise: RCE via Airtable Agent pyodide sandbox bypass -- Aug 13, 2026 HIGH CVE-2026-71962 Flowise: auth bypass leaks private chatflow files 7.5 Aug 10, 2026 HIGH CVE-2026-67620 Flowise: SSRF bypass exposes cloud metadata credentials 7.7 Aug 8, 2026 HIGH CVE-2026-70636 Flowise: auth bypass triggers unauthorized OAuth refresh 7.5 Aug 6, 2026 CRITICAL CVE-2026-67622 Flowise: IDOR in Assistants API leaks OpenAI credentials 9.9 Aug 6, 2026 HIGH CVE-2026-67621 Flowise: broken authz lets viewers poison RAG stores 7.6 Aug 6, 2026 UNKNOWN CVE-2026-70471 Flowise: broken authZ leaks workspace secrets via sandbox -- Aug 4, 2026 HIGH GHSA-88pr-878c-24wf Flowise: S3 loader path traversal enables file write -- Aug 4, 2026 HIGH CVE-2026-70472 Flowise: broken auth exposes cross-tenant OpenAI keys -- Aug 4, 2026 UNKNOWN CVE-2026-70473 Flowise: broken authz leaks Qdrant config, infra data -- Aug 4, 2026 MEDIUM GHSA-rwrp-9823-p2xq Flowise: credential API leaks plaintext DB/cloud secrets 6.5 Aug 4, 2026 HIGH CVE-2026-70474 Flowise: IDOR permite secuestrar credenciales OAuth2 -- Aug 4, 2026 UNKNOWN CVE-2026-70475 Flowise: missing authz lets users tamper executions -- Aug 4, 2026 MEDIUM GHSA-8gj2-2cvc-6xx7 Flowise: missing auth on TTS drains owner's API budget -- Aug 4, 2026 UNKNOWN CVE-2026-70476 Flowise: billing IDOR lets tenants hijack Stripe subs -- Aug 4, 2026 UNKNOWN CVE-2026-70477 Flowise: prompt injection bypasses sandbox for RCE -- Aug 4, 2026

Showing 1–25 of 159

Frequently asked questions

What is Flowise?

Flowise is an AI/ML ai agents tracked by AI Threat Alert for security vulnerabilities in the npm ecosystem.

How many known vulnerabilities does Flowise have?

Flowise has 159 known CVEs, 36 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Flowise distributed in?

Flowise is distributed via the npm ecosystem and categorized as ai agents.

Where does the Flowise vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Flowise?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Flowise in your stack

Get instant alerts when new vulnerabilities affect Flowise. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring