Flowise Vulnerabilities

npm AI Agents

AI Threat Alert tracks 159 known vulnerabilities in Flowise, 36 rated critical — an AI/ML ai agents in the npm ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
159
Total CVEs
36
Critical
npm
Ecosystem
Aug 13, 2026
Last CVE
50%
Patch Rate
2d
Avg Time to Patch

Known Vulnerabilities (159 total, page 2 of 7)

Severity CVE ID Summary CVSS Published
CRITICAL CVE-2026-70478 Flowise: unauth OAuth refresh endpoint leaks access tokens -- Aug 4, 2026 UNKNOWN CVE-2026-70470 Flowise: Unicode homoglyph bypass enables RCE -- Aug 4, 2026 UNKNOWN CVE-2026-69264 Flowise: CSV Agent template injection enables host RCE -- Aug 4, 2026 UNKNOWN CVE-2026-69263 Flowise: env-var bypass reinstates npx auto-exec RCE -- Aug 4, 2026 HIGH CVE-2026-69262 Flowise: broken authz allows cross-type flow deletion -- Aug 4, 2026 UNKNOWN CVE-2026-69259 Flowise: RCE via SQLite path overwrite + root Docker -- Aug 4, 2026 MEDIUM GHSA-2364-jh4q-m9vm Flowise: IDOR exposes customer PII and billing data -- Aug 4, 2026 UNKNOWN CVE-2026-69250 Flowise: unauthenticated SSRF leaks OAuth secrets -- Aug 4, 2026 UNKNOWN CVE-2026-69251 Flowise: TypeORM config injection enables RCE -- Aug 4, 2026 UNKNOWN CVE-2026-69252 Flowise: missing authz allows cross-workspace file wipe -- Aug 4, 2026 CRITICAL CVE-2026-69253 Flowise: code injection in agent tools escapes vm2 sandbox -- Aug 4, 2026 UNKNOWN CVE-2026-69254 Flowise: authenticated RCE as root via NodeVM sandbox escape -- Aug 4, 2026 UNKNOWN CVE-2026-69255 Flowise: code injection in CSVAgent enables root RCE -- Aug 4, 2026 CRITICAL CVE-2026-69256 Flowise: RCE via pickle deserialization in CSVAgent -- Aug 4, 2026 UNKNOWN CVE-2026-69257 Flowise: SSRF via IPv4-mapped IPv6 deny-list bypass -- Aug 4, 2026 HIGH CVE-2026-69258 Flowise: unauth overrideConfig injects flow session state -- Aug 4, 2026 CRITICAL CVE-2026-56271 Flowise: hardcoded JWT secrets enable full auth bypass 9.8 Jul 12, 2026 MEDIUM CVE-2026-56273 Flowise: path traversal in vector store basePath 6.5 Jul 8, 2026 UNKNOWN CVE-2026-56277 Flowise: wildcard CORS on TTS endpoint abuses creds -- Jun 30, 2026 CRITICAL CVE-2026-56278 Flowise: hardcoded default secret enables session forgery 9.1 Jun 30, 2026 MEDIUM CVE-2026-58057 Flowise: NODE_OPTIONS denylist bypass allows RCE 5.0 Jun 28, 2026 CRITICAL CVE-2025-71333 Flowise: unauth file upload + path traversal enables RCE -- Jun 25, 2026 CRITICAL CVE-2025-71336 Flowise: unauthenticated RCE via Custom MCP endpoint 9.8 Jun 25, 2026 HIGH CVE-2025-71335 Flowise: password change fails to revoke sessions 8.1 Jun 25, 2026 CRITICAL CVE-2025-71334 Flowise: path traversal → RCE via missing UUID validation 9.8 Jun 25, 2026

Showing 26–50 of 159

Frequently asked questions

What is Flowise?

Flowise is an AI/ML ai agents tracked by AI Threat Alert for security vulnerabilities in the npm ecosystem.

How many known vulnerabilities does Flowise have?

Flowise has 159 known CVEs, 36 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Flowise distributed in?

Flowise is distributed via the npm ecosystem and categorized as ai agents.

Where does the Flowise vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Flowise?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Flowise in your stack

Get instant alerts when new vulnerabilities affect Flowise. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring