Flowise
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 37 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 28, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
Flowise - Path Traversal in Vector Store basePath Parameter
Flowise - Session Invalidation Failure After Password Change
Flowise - Unsandboxed Remote Code Execution via Custom MCP
Flowise - Arbitrary File Access via Missing Chat Flow ID Validation
Flowise - Arbitrary File Read via chatId Parameter
Flowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess
Monitor Flowise in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.