Where
-Infinity
0

Flowise FlowiseFlowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history

Risk 53
Severity
8.3
First published (updated )

Flowise FlowiseFlowise: Pyodide validator Unicode homoglyph bypass leads to RCE

Risk 80
Severity
9.5
First published (updated )

Flowise FlowiseFlowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation

Risk 81
Severity
9.4
First published (updated )

Flowise FlowiseFlowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)

Risk 79
Severity
8.7
First published (updated )

Flowise FlowiseFlowise - Path Traversal in Vector Store basePath Parameter

Risk 38
Severity
4.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Flowise FlowiseFlowise - Session Invalidation Failure After Password Change

Risk 62
Severity
8.6
First published (updated )

Flowise FlowiseFlowise - Unsandboxed Remote Code Execution via Custom MCP

Risk 86
Severity
9.3
First published (updated )

Flowise FlowiseFlowise - Arbitrary File Access via Missing Chat Flow ID Validation

Risk 86
Severity
9.3
First published (updated )

Flowise FlowiseFlowise - Arbitrary File Read via chatId Parameter

Risk 47
Severity
8.7
First published (updated )

Flowise FlowiseFlowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess

Risk 82
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Flowise FlowiseFlowise - Unverified Email Change via Account Profile Endpoint

Risk 71
Severity
8.7
First published (updated )

Flowise FlowiseFlowise - Cross-Workspace Information Disclosure via chatflows/apikey Endpoint

Risk 44
Severity
5.3
First published (updated )

Flowise FlowiseFlowise - PII Disclosure via Unauthenticated Forgot Password Endpoint

Risk 41
Severity
6.9
First published (updated )

Flowise FlowiseFlowise - Cross-Site Scripting in Chat Messages and Agent Workflows

Risk 38
Severity
5.1
First published (updated )

Flowise FlowiseFlowise AccountService resetPassword Authentication Bypass Vulnerability

Risk 84
First published (updated )
Advisory
ZDI-26-300
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Flowise FlowiseFlowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability

Risk 86
Severity
9.2
First published (updated )

Flowise FlowiseFlowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials

Risk 43
Severity
8.2
First published (updated )

Flowise FlowiseFlowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs

Risk 47
Severity
8.7
First published (updated )

Flowise FlowiseFlowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)

Risk 79
Severity
7.6
First published (updated )

Flowise FlowiseFlowise: Password Reset Link Sent Over Unsecured HTTP

Risk 69
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Flowise FlowiseFlowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow

Risk 54
Severity
7.7
First published (updated )

Flowise Flowise CloudFlowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association

Risk 86
Severity
9.8
First published (updated )

Flowise FlowiseFlowise: Sensitive Data Leak in public-chatbotConfig

Risk 46
Severity
7.7
First published (updated )

Flowise FlowiseFlowise: Code Injection in CSVAgent leads to Authenticated RCE

Risk 81
Severity
9.4
First published (updated )

BleepingComputerMax severity Flowise RCE vulnerability now exploited in attacks

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed

First published (updated )
Social
reddit

Flowise FlowiseCommand Injection

Risk 40
Severity
6.5
First published (updated )

Flowise FlowiseFlowise Authenticated Command Execution and Sandbox Bypass via Puppeteer & Playwright Packages

Risk 82
Severity
8.4
First published (updated )

Flowise FlowiseFlowise is vulnerable to arbitrary file read, arbitrary file write

Risk 83
Severity
10
First published (updated )

Flowise FlowiseXSS

Risk 53
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203