Flowise
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 45 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 28, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Flowise before 3.1.3 Credential Exposure via API
Flowise before 3.1.4 Credential Abuse via Text-to-Speech
Flowise before 3.1.3 Sandbox Escape to RCE
Flowise before 3.1.3 Prompt Injection RCE via CSV Agent
Flowise before 3.1.3 Remote Code Execution via Airtable Agent
Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download
Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List
Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
Monitor Flowise in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.