Vulnerabilidades en Flowise

25 resultados
Análisis Vexday

Flowise apresenta 25 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando produto em fase de descoberta ativa de falhas de segurança. Oito dessas vulnerabilidades atingem nível crítico, com a fraqueza dominante sendo CWE-73 (uso externo de controle/dados), mas nenhuma está sob exploração ativa documentada no KEV. O risco concentra-se em ambientes de produção que não atualizarem regularmente.

CVE-2026-56274HIGHFlowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccessEPSS 7.5%CVE-2025-71334CRITICALFlowise - Arbitrary File Access via Missing Chat Flow ID ValidationEPSS 4.4%CVE-2026-56270HIGHFlowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod EndpointEPSS 2.0%CVE-2025-71324HIGHFlowise - Arbitrary File Read via chatId ParameterEPSS 1.6%CVE-2026-58057LOWFlowise - Custom MCP Environment Variable Denylist Bypass via Case SensitivityEPSS 1.6%CVE-2025-71338CRITICALFlowise through 2.2.7 - Arbitrary File Write to Remote Code Execution via document-store APIEPSS 1.2%CVE-2025-71336CRITICALFlowise - Unsandboxed Remote Code Execution via Custom MCPEPSS 1.1%CVE-2024-58351CRITICALFlowise - Remote Code Execution via overrideConfig ParameterEPSS 0.9%CVE-2025-71333CRITICALFlowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments EndpointEPSS 0.9%CVE-2025-71327CRITICALFlowise - Authentication Bypass via Unprotected Registration EndpointEPSS 0.7%CVE-2026-56271CRITICALFlowise - Weak Default JWT Secrets in Authentication MiddlewareEPSS 0.7%CVE-2026-56278CRITICALFlowise - Session Hijacking via Weak Default Express Session SecretEPSS 0.5%CVE-2025-71332HIGHFlowise - SQL Injection in importChatflows API via chatflow.id ParameterEPSS 0.5%CVE-2026-56273MEDIUMFlowise - Path Traversal in Vector Store basePath ParameterEPSS 0.5%CVE-2025-71328HIGHFlowise - Unverified Password Change via Account SettingsEPSS 0.5%CVE-2026-56267MEDIUMFlowise - PII Disclosure via Unauthenticated Forgot Password EndpointEPSS 0.5%CVE-2025-71337HIGHFlowise - Unverified Email Change via Account Profile EndpointEPSS 0.4%CVE-2026-56268MEDIUMFlowise - Cross-Workspace Information Disclosure via chatflows/apikey EndpointEPSS 0.4%CVE-2025-71335HIGHFlowise - Session Invalidation Failure After Password ChangeEPSS 0.4%CVE-2026-56276MEDIUMFlowise - Mass Assignment in PUT /api/v1/user Allows Password Hash OverrideEPSS 0.4%