Technology · npm
flowise (npm) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 156 vulnerabilities in flowise (npm): 0 in the last 7 days and 43 in the last 90 days, 29 of them critical and 0 exploited in the wild. The most recent, CVE-2026-91931, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 43
- Critical, all time
- 29
- Exploited in the wild
- 0
About flowise (npm)
A low-code tool for building customized LLM orchestration flows and AI agents.
Latest flowise (npm) vulnerabilities
- CVE-2026-91931: Flowise Custom MCP remote code execution via npxhighCVSS 8.5EPSS 0.7%
- CVE-2026-91930: Flowise cross-tenant organization admin takeover via unscoped membership APIshighCVSS 7.5EPSS 0.4%
- CVE-2026-91929: Flowise cross-tenant authorization bypass in Enterprise endpointshighCVSS 7.1EPSS 0.4%
- CVE-2026-90533: Flowise broken access control in GET /api/v1/organizationusermediumCVSS 6.5EPSS 0.3%
- CVE-2026-73604: Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint…mediumCVSS 6.5EPSS 0.4%
- CVE-2026-73603: Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing…mediumCVSS 5.3EPSS 0.3%
- CVE-2026-73488: Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET…mediumCVSS 6.5EPSS 0.4%
- CVE-2026-73486: Flowise CSV Agent code injection via customReadCSVhighCVSS 8.8EPSS 0.7%
- CVE-2026-73485: Flowise Airtable Agent code injection in pyodidehighCVSS 8.8EPSS 0.6%
- CVE-2026-73483: Flowise sandbox escape via puppeteer in NodeVMhighCVSS 8.8EPSS 0.7%
- CVE-2026-67620: Flowise server-side request forgery in metadata service guardhighCVSS 7.7EPSS 0.5%
- CVE-2026-67621: Flowise missing authorization in document store operationshighCVSS 7.6EPSS 0.4%
- CVE-2026-70478: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST…criticalCVSS 10EPSS 0.6%
- CVE-2026-70477: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt…criticalCVSS 9.8EPSS 0.8%
- CVE-2026-70476: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several…highCVSS 8.2EPSS 0.5%
- CVE-2026-70475: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT…highCVSS 6.5EPSS 0.5%
- Flowise missing authorization in Text-to-Speech endpointmediumCVSS 6.3
- CVE-2026-70474: Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3…highCVSS 8.1EPSS 0.5%
- CVE-2026-70473: Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3…highCVSS 8.5EPSS 0.4%
- CVE-2026-70472: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise…highCVSS 8.8EPSS 0.5%
- CVE-2026-70471: Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3…highCVSS 6.5EPSS 0.4%
- CVE-2026-70470: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise…criticalCVSS 9.8EPSS 1.0%
- CVE-2026-69264: Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a…criticalCVSS 9.8EPSS 1.1%
- Flowise incomplete credential redaction in credentials APImediumCVSS 6.5
- Flowise arbitrary file write via path traversal in S3 document loadershighCVSS 7.2
Most severe flowise (npm) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-71338: Flowise path traversal and arbitrary file write in document-store APIcriticalCVSS 10EPSS 1.2%
- CVE-2026-70478: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST…criticalCVSS 10EPSS 0.6%
- CVE-2026-56274: Flowise OS command injection in Custom MCP Server featurecriticalCVSS 9.9EPSS 7.5%
- CVE-2025-34267: Flowise remote code execution via Puppeteer and Playwright sandbox escapecriticalCVSS 9.9EPSS 6.6%
- CVE-2026-40933: Flowise Flowise authenticated RCE in MCP AdapterscriticalCVSS 9.9EPSS 1.3%
- FlowiseAI authenticated RCE via NodeVM sandbox escape in custom functioncriticalCVSS 9.9
- CVE-2025-71334: FlowiseAI Flowise arbitrary file access and path traversalcriticalCVSS 9.8EPSS 4.4%
- CVE-2026-41264: Flowise: CSV Agent Prompt Injection Remote Code Execution VulnerabilitycriticalCVSS 9.8EPSS 1.2%
- CVE-2025-71336: Flowise remote code execution in Custom MCP featurecriticalCVSS 9.8EPSS 1.1%
- CVE-2026-69264: Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a…criticalCVSS 9.8EPSS 1.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 2 | 1 | |
| 6 Jul 2026 | 2 | 1 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 29 | 11 | |
| 10 Aug 2026 | 6 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 3 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/flowise.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "flowise (npm) vulnerabilities", https://junglewise.ai/threats/technologies/flowise, 26 September 2026.