{"schema_version":1,"title":"Flowise vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 20 vulnerabilities in Flowise: 1 in the last 7 days and 11 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100608, was published on 26 September 2026.","url":"https://junglewise.ai/threats/vendors/flowise","json_url":"https://junglewise.ai/threats/vendors/flowise.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/flowise","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":12,"all_time":20,"critical":1,"exploited":0,"last_7_days":1,"last_30_days":5,"last_90_days":11,"last_365_days":19},"latest":[{"cve":"CVE-2026-100608","cvss":8.3,"slug":"cve-2026-100608-flowise-through-3-1-4-does-not-enforce-authorization-on-the","title":"Flowise authorization bypass in BullMQ admin dashboard","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:41.14+00:00","url":"https://junglewise.ai/threats/cve-2026-100608-flowise-through-3-1-4-does-not-enforce-authorization-on-the"},{"cve":"CVE-2026-91931","cvss":8.5,"epss":0.0068,"slug":"cve-2026-91931-flowise-custom-mcp-remote-code-execution-via-npx","title":"Flowise Custom MCP remote code execution via npx","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:43.883+00:00","url":"https://junglewise.ai/threats/cve-2026-91931-flowise-custom-mcp-remote-code-execution-via-npx"},{"cve":"CVE-2026-91930","cvss":7.5,"epss":0.004,"slug":"cve-2026-91930-flowise-cross-tenant-organization-admin-takeover-via-unscoped","title":"Flowise cross-tenant organization admin takeover via unscoped membership APIs","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:43.743+00:00","url":"https://junglewise.ai/threats/cve-2026-91930-flowise-cross-tenant-organization-admin-takeover-via-unscoped"},{"cve":"CVE-2026-91929","cvss":7.1,"epss":0.0035,"slug":"cve-2026-91929-flowise-cross-tenant-authorization-bypass-in-enterprise-endpoints","title":"Flowise cross-tenant authorization bypass in Enterprise endpoints","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:43.187+00:00","url":"https://junglewise.ai/threats/cve-2026-91929-flowise-cross-tenant-authorization-bypass-in-enterprise-endpoints"},{"cve":"CVE-2026-90533","cvss":6.5,"epss":0.0034,"slug":"cve-2026-90533-flowise-broken-access-control-in-get-api-v1-organizationuser","title":"Flowise broken access control in GET /api/v1/organizationuser","severity":"medium","exploited":false,"published_at":"2026-09-12T13:16:51.1+00:00","url":"https://junglewise.ai/threats/cve-2026-90533-flowise-broken-access-control-in-get-api-v1-organizationuser"},{"cve":"CVE-2026-73603","cvss":5.3,"epss":0.0033,"slug":"cve-2026-73603-flowise-text-to-speech-endpoint-credential-abuse-via","title":"Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse priva","severity":"medium","exploited":false,"published_at":"2026-08-13T12:17:24.617+00:00","url":"https://junglewise.ai/threats/cve-2026-73603-flowise-text-to-speech-endpoint-credential-abuse-via"},{"cve":"CVE-2026-73486","cvss":8.8,"epss":0.0066,"slug":"cve-2026-73486-flowise-csv-agent-code-injection-via-customreadcsv","title":"Flowise CSV Agent code injection via customReadCSV","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:23.947+00:00","url":"https://junglewise.ai/threats/cve-2026-73486-flowise-csv-agent-code-injection-via-customreadcsv"},{"cve":"CVE-2026-73485","cvss":8.8,"epss":0.006,"slug":"cve-2026-73485-flowise-airtable-agent-code-injection-in-pyodide","title":"Flowise Airtable Agent code injection in pyodide","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:23.807+00:00","url":"https://junglewise.ai/threats/cve-2026-73485-flowise-airtable-agent-code-injection-in-pyodide"},{"cve":"CVE-2026-73483","cvss":8.8,"epss":0.0074,"slug":"cve-2026-73483-flowise-sandbox-escape-via-puppeteer-in-nodevm","title":"Flowise sandbox escape via puppeteer in NodeVM","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:23.54+00:00","url":"https://junglewise.ai/threats/cve-2026-73483-flowise-sandbox-escape-via-puppeteer-in-nodevm"},{"cve":"CVE-2026-67620","cvss":7.7,"epss":0.0046,"slug":"cve-2026-67620-flowise-server-side-request-forgery-in-metadata-service-guard","title":"Flowise server-side request forgery in metadata service guard","severity":"high","exploited":false,"published_at":"2026-08-08T16:16:49.42+00:00","url":"https://junglewise.ai/threats/cve-2026-67620-flowise-server-side-request-forgery-in-metadata-service-guard"},{"cve":"CVE-2026-67621","cvss":7.6,"epss":0.0042,"slug":"cve-2026-67621-flowise-missing-authorization-in-document-store-operations","title":"Flowise missing authorization in document store operations","severity":"high","exploited":false,"published_at":"2026-08-06T22:18:22.717+00:00","url":"https://junglewise.ai/threats/cve-2026-67621-flowise-missing-authorization-in-document-store-operations"},{"cvss":3.1,"slug":"flowise-execute-flow-ssrf-in-base-url-configuration-fac4f0c1","title":"Flowise Execute Flow SSRF in base URL configuration","severity":"low","exploited":false,"published_at":"2026-06-23T15:32:36+00:00","url":"https://junglewise.ai/threats/flowise-execute-flow-ssrf-in-base-url-configuration-fac4f0c1"},{"cvss":7.1,"slug":"flowise-execute-flow-node-server-side-request-forgery-198e44fc","title":"Flowise Execute Flow node server-side request forgery","severity":"high","exploited":false,"published_at":"2026-06-23T15:32:36+00:00","url":"https://junglewise.ai/threats/flowise-execute-flow-node-server-side-request-forgery-198e44fc"},{"cvss":9.8,"slug":"flowise-overrideconfig-remote-code-execution-via-code-injection-ee9d20bf","title":"Flowise OverrideConfig remote code execution via code injection","severity":"critical","exploited":false,"published_at":"2026-06-20T18:31:28+00:00","url":"https://junglewise.ai/threats/flowise-overrideconfig-remote-code-execution-via-code-injection-ee9d20bf"},{"cve":"CVE-2026-41268","cvss":7.7,"epss":0.0125,"slug":"cve-2026-41268-flowise-parameter-override-bypass-remote-command-execution","title":"Flowise: Parameter Override Bypass Remote Command Execution","severity":"high","exploited":false,"published_at":"2026-04-16T21:46:39+00:00","url":"https://junglewise.ai/threats/cve-2026-41268-flowise-parameter-override-bypass-remote-command-execution"},{"cve":"CVE-2026-41137","cvss":8.8,"epss":0.0205,"slug":"cve-2026-41137-flowise-code-injection-in-csvagent-leads-to-authenticated-rce","title":"Flowise: Code Injection in CSVAgent leads to Authenticated RCE","severity":"high","exploited":false,"published_at":"2026-04-16T21:44:15+00:00","url":"https://junglewise.ai/threats/cve-2026-41137-flowise-code-injection-in-csvagent-leads-to-authenticated-rce"},{"cve":"CVE-2026-30822","cvss":3,"epss":0.0046,"slug":"cve-2026-30822-flowise-mass-assignment-in-api-v1-leads-endpoint","title":"Flowise mass assignment in /api/v1/leads endpoint","severity":"low","exploited":false,"published_at":"2026-03-06T22:19:14+00:00","url":"https://junglewise.ai/threats/cve-2026-30822-flowise-mass-assignment-in-api-v1-leads-endpoint"},{"cvss":3.1,"slug":"flowise-readfiletool-arbitrary-file-read-d9b723ac","title":"Flowise ReadFileTool arbitrary file read","severity":"low","exploited":false,"published_at":"2025-10-10T22:55:09+00:00","url":"https://junglewise.ai/threats/flowise-readfiletool-arbitrary-file-read-d9b723ac"},{"cve":"CVE-2025-61913","cvss":3.1,"epss":0.1295,"slug":"cve-2025-61913-flowise-writefiletool-arbitrary-file-write-vulnerability","title":"Flowise WriteFileTool arbitrary file write vulnerability","severity":"low","exploited":false,"published_at":"2025-10-09T15:21:39+00:00","url":"https://junglewise.ai/threats/cve-2025-61913-flowise-writefiletool-arbitrary-file-write-vulnerability"},{"cve":"CVE-2024-8182","cvss":3.1,"epss":0.1389,"slug":"cve-2024-8182-flowise-unauthenticated-denial-of-service-in-file-upload-endpoint","title":"Flowise unauthenticated denial of service in file upload endpoint","severity":"low","exploited":false,"published_at":"2024-08-27T15:32:51+00:00","url":"https://junglewise.ai/threats/cve-2024-8182-flowise-unauthenticated-denial-of-service-in-file-upload-endpoint"}],"vendor":{"hub":true,"name":"Flowise","slug":"flowise","description":"Low-code platform for building AI chatbots and workflow automation using LLMs.","url":"https://junglewise.ai/threats/vendors/flowise"},"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cvss":9.8,"slug":"flowise-overrideconfig-remote-code-execution-via-code-injection-ee9d20bf","title":"Flowise OverrideConfig remote code execution via code injection","severity":"critical","exploited":false,"published_at":"2026-06-20T18:31:28+00:00","url":"https://junglewise.ai/threats/flowise-overrideconfig-remote-code-execution-via-code-injection-ee9d20bf"},{"cve":"CVE-2026-41137","cvss":8.8,"epss":0.0205,"slug":"cve-2026-41137-flowise-code-injection-in-csvagent-leads-to-authenticated-rce","title":"Flowise: Code Injection in CSVAgent leads to Authenticated RCE","severity":"high","exploited":false,"published_at":"2026-04-16T21:44:15+00:00","url":"https://junglewise.ai/threats/cve-2026-41137-flowise-code-injection-in-csvagent-leads-to-authenticated-rce"},{"cve":"CVE-2026-73483","cvss":8.8,"epss":0.0074,"slug":"cve-2026-73483-flowise-sandbox-escape-via-puppeteer-in-nodevm","title":"Flowise sandbox escape via puppeteer in NodeVM","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:23.54+00:00","url":"https://junglewise.ai/threats/cve-2026-73483-flowise-sandbox-escape-via-puppeteer-in-nodevm"},{"cve":"CVE-2026-73486","cvss":8.8,"epss":0.0066,"slug":"cve-2026-73486-flowise-csv-agent-code-injection-via-customreadcsv","title":"Flowise CSV Agent code injection via customReadCSV","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:23.947+00:00","url":"https://junglewise.ai/threats/cve-2026-73486-flowise-csv-agent-code-injection-via-customreadcsv"},{"cve":"CVE-2026-73485","cvss":8.8,"epss":0.006,"slug":"cve-2026-73485-flowise-airtable-agent-code-injection-in-pyodide","title":"Flowise Airtable Agent code injection in pyodide","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:23.807+00:00","url":"https://junglewise.ai/threats/cve-2026-73485-flowise-airtable-agent-code-injection-in-pyodide"},{"cve":"CVE-2026-91931","cvss":8.5,"epss":0.0068,"slug":"cve-2026-91931-flowise-custom-mcp-remote-code-execution-via-npx","title":"Flowise Custom MCP remote code execution via npx","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:43.883+00:00","url":"https://junglewise.ai/threats/cve-2026-91931-flowise-custom-mcp-remote-code-execution-via-npx"},{"cve":"CVE-2026-100608","cvss":8.3,"slug":"cve-2026-100608-flowise-through-3-1-4-does-not-enforce-authorization-on-the","title":"Flowise authorization bypass in BullMQ admin dashboard","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:41.14+00:00","url":"https://junglewise.ai/threats/cve-2026-100608-flowise-through-3-1-4-does-not-enforce-authorization-on-the"},{"cve":"CVE-2026-41268","cvss":7.7,"epss":0.0125,"slug":"cve-2026-41268-flowise-parameter-override-bypass-remote-command-execution","title":"Flowise: Parameter Override Bypass Remote Command Execution","severity":"high","exploited":false,"published_at":"2026-04-16T21:46:39+00:00","url":"https://junglewise.ai/threats/cve-2026-41268-flowise-parameter-override-bypass-remote-command-execution"},{"cve":"CVE-2026-67620","cvss":7.7,"epss":0.0046,"slug":"cve-2026-67620-flowise-server-side-request-forgery-in-metadata-service-guard","title":"Flowise server-side request forgery in metadata service guard","severity":"high","exploited":false,"published_at":"2026-08-08T16:16:49.42+00:00","url":"https://junglewise.ai/threats/cve-2026-67620-flowise-server-side-request-forgery-in-metadata-service-guard"},{"cve":"CVE-2026-67621","cvss":7.6,"epss":0.0042,"slug":"cve-2026-67621-flowise-missing-authorization-in-document-store-operations","title":"Flowise missing authorization in document store operations","severity":"high","exploited":false,"published_at":"2026-08-06T22:18:22.717+00:00","url":"https://junglewise.ai/threats/cve-2026-67621-flowise-missing-authorization-in-document-store-operations"}],"generated_at":"2026-09-28T03:07:00.154823+00:00","technologies":[]}