Flowise
AI Threat Alert tracks 23 known AI/ML vulnerabilities affecting Flowise products — each enriched with CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis. Browse every Flowise CVE below, sorted by severity and recency.
| Severity | CVE | Headline | Package | CVSS |
|---|---|---|---|---|
| CRITICAL | CVE-2024-58351 | Flowise: RCE and sandbox escape via overrideConfig | Flowise | 9.8 |
| MEDIUM | CVE-2025-71331 | Flowise: XSS enables session hijacking in AI agent UI | Flowise | 6.1 |
| MEDIUM | CVE-2026-56267 | Flowise: PII exposure via unauthenticated password reset | Flowise | - |
| MEDIUM | CVE-2026-56276 | Flowise: mass assignment enables credential hash override | Flowise | - |
| HIGH | CVE-2026-56268 | Flowise: cross-workspace chatflow config disclosure | Flowise | 7.7 |
| HIGH | CVE-2025-71337 | Flowise: account takeover via unverified email change | Flowise | 8.3 |
| UNKNOWN | CVE-2026-56275 | Flowise: SSRF bypasses security check in Execute Flow | Flowise | - |
| CRITICAL | CVE-2026-56274 | Flowise: RCE via MCP server command validation bypass | Flowise | 9.9 |
| MEDIUM | CVE-2025-71332 | Flowise: SQL injection exposes AI credential store | Flowise | 6.5 |
| MEDIUM | CVE-2026-56272 | Flowise: weak bcrypt enables 30x faster password cracking | Flowise | 4.1 |
| MEDIUM | CVE-2026-56269 | Flowise: hardcoded JWT secret leaks user/workspace IDs | Flowise | 4.6 |
| HIGH | CVE-2026-56270 | Flowise: auth bypass exposes OAuth secrets in cleartext | Flowise | 7.5 |
| CRITICAL | CVE-2025-71327 | Flowise: auth bypass grants full API access | Flowise | 9.1 |
| HIGH | CVE-2025-71324 | Flowise: path traversal leaks database unauthenticated | Flowise | 7.5 |
| HIGH | CVE-2025-71328 | Flowise: unverified password change enables account takeover | Flowise | 8.3 |
| CRITICAL | CVE-2025-71338 | Flowise: unauthenticated file write enables RCE | Flowise | 10.0 |
| CRITICAL | CVE-2025-71334 | Flowise: path traversal → RCE via missing UUID validation | Flowise | 9.8 |
| HIGH | CVE-2025-71335 | Flowise: password change fails to revoke sessions | Flowise | 8.1 |
| CRITICAL | CVE-2025-71336 | Flowise: unauthenticated RCE via Custom MCP endpoint | Flowise | 9.8 |
| CRITICAL | CVE-2025-71333 | Flowise: unauth file upload + path traversal enables RCE | Flowise | - |
Page 1 of 2
Frequently asked questions
How many known vulnerabilities affect Flowise?
23 AI/ML CVEs affecting Flowise products are tracked, sourced from NVD and GitHub Advisory.
What Flowise products are affected?
The CVEs below map to the Flowise AI/ML packages and tools tracked by AI Threat Alert; open any CVE to see the affected components and versions.
Where does the Flowise vulnerability data come from?
Data is sourced from NVD and GitHub Advisory, then enriched with CVSS severity, EPSS exploit probability, and patch status for each CVE.
How can I monitor Flowise for new vulnerabilities?
AI Threat Alert tracks Flowise continuously; a Pro subscription adds breaking alerts when new CVEs affecting Flowise are published.
How do I assess Flowise's security exposure?
Each CVE below carries CVSS severity and exploitation signals, so you can review the highest-severity Flowise issues first and judge the exposure for your stack.