Flowiseai maintains a narrowly focused vulnerability footprint centered on its Flowise low-code AI application platform and embedding tools, which despite modest product scope have achieved prominence in the emerging AI-application development landscape. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the combination of web-facing interfaces, user-supplied configuration, and access to backend AI model execution. The recurring exposure patterns cluster around dynamic attribute manipulation, authorization bypass through user-controlled keys, improper access control, cross-site scripting, and server-side request forgery—weakness classes that are characteristic of web frameworks handling untrusted model configurations and integration chains. Defenders deploying Flowise instances should apply updates urgently given the severity profile and treat exposed interfaces as high-priority targets; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flowiseai over time
Signals from CVEs in this vendor scope (86 CVEs).
86 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59528CRITICAL Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows | Sep 22, 2025 | 10.0 | 95 | NO | YES |
CVE-2025-8943CRITICAL The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and author | Aug 14, 2025 | 9.8 | 87 | NO | YES |
CVE-2025-58434CRITICAL Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint in Flowise returns sensitive i | Sep 12, 2025 | 9.8 | 80 | NO | YES |
CVE-2025-26319CRITICAL FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments. | Mar 4, 2025 | 9.8 | 72 | NO | YES |
CVE-2024-31621HIGH An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component. | Apr 29, 2024 | 7.6 | 72 | NO | YES |
CVE-2026-30824CRITICAL Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvidia-nim/*) is whitelisted in the | Mar 7, 2026 | 9.8 | 64 | NO | YES |
CVE-2024-8181HIGH An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow th | Aug 27, 2024 | 8.1 | 59 | NO | YES |
CVE-2026-46442CRITICAL Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, | Jun 8, 2026 | 9.9 | 53 | NO | YES |
CVE-2026-41264CRITICAL Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the CSV_Agents class. The | Apr 23, 2026 | 9.8 | 45 | NO | YES |
CVE-2026-56271CRITICAL Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENC | Jul 12, 2026 | 9.8 | 44 | NO | NO |
Signals from CVEs in this vendor scope (86 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flowiseai.
Media articles that mention a CVE ID that affects a product developed by Flowiseai — matched by CVE ID, not by vendor name.