Vendor
Flowise vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 20 vulnerabilities in Flowise: 1 in the last 7 days and 11 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100608, was published on 26 September 2026.
- Last 7 days
- 1
- Last 90 days
- 11
- Critical, all time
- 1
- Exploited in the wild
- 0
About Flowise
Low-code platform for building AI chatbots and workflow automation using LLMs.
Latest Flowise vulnerabilities
- CVE-2026-100608: Flowise authorization bypass in BullMQ admin dashboardhighCVSS 8.3
- CVE-2026-91931: Flowise Custom MCP remote code execution via npxhighCVSS 8.5EPSS 0.7%
- CVE-2026-91930: Flowise cross-tenant organization admin takeover via unscoped membership APIshighCVSS 7.5EPSS 0.4%
- CVE-2026-91929: Flowise cross-tenant authorization bypass in Enterprise endpointshighCVSS 7.1EPSS 0.4%
- CVE-2026-90533: Flowise broken access control in GET /api/v1/organizationusermediumCVSS 6.5EPSS 0.3%
- CVE-2026-73603: Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing…mediumCVSS 5.3EPSS 0.3%
- CVE-2026-73486: Flowise CSV Agent code injection via customReadCSVhighCVSS 8.8EPSS 0.7%
- CVE-2026-73485: Flowise Airtable Agent code injection in pyodidehighCVSS 8.8EPSS 0.6%
- CVE-2026-73483: Flowise sandbox escape via puppeteer in NodeVMhighCVSS 8.8EPSS 0.7%
- CVE-2026-67620: Flowise server-side request forgery in metadata service guardhighCVSS 7.7EPSS 0.5%
- CVE-2026-67621: Flowise missing authorization in document store operationshighCVSS 7.6EPSS 0.4%
- Flowise Execute Flow SSRF in base URL configurationlowCVSS 3.1
- Flowise Execute Flow node server-side request forgeryhighCVSS 7.1
- Flowise OverrideConfig remote code execution via code injectioncriticalCVSS 9.8
- CVE-2026-41268: Flowise: Parameter Override Bypass Remote Command ExecutionhighCVSS 7.7EPSS 1.3%
- CVE-2026-41137: Flowise: Code Injection in CSVAgent leads to Authenticated RCEhighCVSS 8.8EPSS 2.1%
- CVE-2026-30822: Flowise mass assignment in /api/v1/leads endpointlowCVSS 3EPSS 0.5%
- Flowise ReadFileTool arbitrary file readlowCVSS 3.1
- CVE-2025-61913: Flowise WriteFileTool arbitrary file write vulnerabilitylowCVSS 3.1EPSS 13.0%
- CVE-2024-8182: Flowise unauthenticated denial of service in file upload endpointlowCVSS 3.1EPSS 13.9%
Most severe Flowise vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- Flowise OverrideConfig remote code execution via code injectioncriticalCVSS 9.8
- CVE-2026-41137: Flowise: Code Injection in CSVAgent leads to Authenticated RCEhighCVSS 8.8EPSS 2.1%
- CVE-2026-73483: Flowise sandbox escape via puppeteer in NodeVMhighCVSS 8.8EPSS 0.7%
- CVE-2026-73486: Flowise CSV Agent code injection via customReadCSVhighCVSS 8.8EPSS 0.7%
- CVE-2026-73485: Flowise Airtable Agent code injection in pyodidehighCVSS 8.8EPSS 0.6%
- CVE-2026-91931: Flowise Custom MCP remote code execution via npxhighCVSS 8.5EPSS 0.7%
- CVE-2026-100608: Flowise authorization bypass in BullMQ admin dashboardhighCVSS 8.3
- CVE-2026-41268: Flowise: Parameter Override Bypass Remote Command ExecutionhighCVSS 7.7EPSS 1.3%
- CVE-2026-67620: Flowise server-side request forgery in metadata service guardhighCVSS 7.7EPSS 0.5%
- CVE-2026-67621: Flowise missing authorization in document store operationshighCVSS 7.6EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 2 | 0 | |
| 10 Aug 2026 | 4 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 3 | 0 | |
| 21 Sep 2026 | 1 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/flowise.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Flowise vulnerabilities", https://junglewise.ai/threats/vendors/flowise, 28 September 2026.