Where
-Infinity
0

Vendor Risk Score

See how flowiseai compares to other vendors in security performance

View Risk Score →

FlowiseFlowise - Weak Default JWT Secrets in Authentication Middleware

Risk 86
Severity
9.3
First published (updated )

FlowiseFlowise - Hardcoded CORS Wildcard in TTS Endpoint

Risk 41
Severity
6.9
First published (updated )

FlowiseFlowise - Session Hijacking via Weak Default Express Session Secret

Risk 67
Severity
9.3
First published (updated )

FlowiseFlowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity

Risk 65
Severity
2.3
First published (updated )

FlowiseFlowise - Arbitrary File Write to Remote Code Execution via document-store API

Risk 87
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Flowise FlowiseFlowise - Session Invalidation Failure After Password Change

Risk 62
Severity
8.6
First published (updated )

Flowise FlowiseFlowise - Unsandboxed Remote Code Execution via Custom MCP

Risk 86
Severity
9.3
First published (updated )

Flowise FlowiseFlowise - Arbitrary File Access via Missing Chat Flow ID Validation

Risk 86
Severity
9.3
First published (updated )

FlowiseFlowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint

Risk 86
Severity
9.3
First published (updated )

FlowiseFlowise - Unverified Password Change via Account Settings

Risk 79
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

FlowiseFlowise - Authentication Bypass via Unprotected Registration Endpoint

Risk 67
Severity
9.3
First published (updated )

Flowise FlowiseFlowise - Arbitrary File Read via chatId Parameter

Risk 47
Severity
8.7
First published (updated )

npm/flowiseFlowise - Insufficient Password Salt Rounds in Bcrypt Hashing

Risk 29
Severity
5.6
First published (updated )

npm/flowiseFlowise - Weak Default Token Hash Secret in JWT Token Encryption

Risk 30
Severity
4.3
First published (updated )

FlowiseAI FlowiseFlowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint

Risk 47
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/flowiseFlowise - SQL Injection in importChatflows API via chatflow.id Parameter

Risk 79
Severity
8.5
First published (updated )

FlowiseAI Flowise CSV AgentZDI-26-365: FlowiseAI Flowise CSV Agent customReadCSV Code Injection Remote Code Execution Vulnerability

Risk 89
First published (updated )

FlowiseAI Flowise CSV AgentFlowiseAI Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability

Risk 95
First published (updated )
Advisory
ZDI-26-364

FlowiseAI Flowise CSV AgentZDI-26-364: FlowiseAI Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability

Risk 95
First published (updated )

FlowiseAI FlowiseFlowiseAI Flowise CSV Agent customReadCSV Code Injection Remote Code Execution Vulnerability

Risk 89
First published (updated )
Advisory
ZDI-26-365
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/flowiseFlowise - Server-Side Request Forgery via Execute Flow Base URL

Risk 48
Severity
6
First published (updated )

Flowise FlowiseFlowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess

Risk 82
Severity
8.7
First published (updated )

Flowise FlowiseFlowise - Unverified Email Change via Account Profile Endpoint

Risk 71
Severity
8.7
First published (updated )

Flowise FlowiseFlowise - Cross-Workspace Information Disclosure via chatflows/apikey Endpoint

Risk 44
Severity
5.3
First published (updated )

FlowiseAI FlowiseFlowiseAI Flowise S3 Document Loader S3.ts path traversal

Risk 46
Severity
2.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Flowise FlowiseFlowise - Cross-Site Scripting in Chat Messages and Agent Workflows

Risk 38
Severity
5.1
First published (updated )

npm/flowiseFlowise: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover

Risk 79
Severity
7.7
First published (updated )

npm/flowiseFlowise: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover

Risk 79
Severity
7.7
First published (updated )

npm/flowiseFlowise: DatasetRow create+update mass-assignment allows cross-workspace row takeover

Risk 79
Severity
7.7
First published (updated )

npm/flowiseFlowise: Dataset create+update mass-assignment allows cross-workspace dataset takeover

Risk 79
Severity
7.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203