Vulnerabilidades em Flowise

25 resultados
Análise Vexday

Flowise apresenta 25 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando produto em fase de descoberta ativa de falhas de segurança. Oito dessas vulnerabilidades atingem nível crítico, com a fraqueza dominante sendo CWE-73 (uso externo de controle/dados), mas nenhuma está sob exploração ativa documentada no KEV. O risco concentra-se em ambientes de produção que não atualizarem regularmente.

CVE-2025-71334CRITICALFlowise - Arbitrary File Access via Missing Chat Flow ID ValidationEPSS 3.9%CVE-2026-56274HIGHFlowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccessEPSS 3.3%CVE-2025-71336CRITICALFlowise - Unsandboxed Remote Code Execution via Custom MCPEPSS 1.6%CVE-2025-71324HIGHFlowise - Arbitrary File Read via chatId ParameterEPSS 1.4%CVE-2026-58057LOWFlowise - Custom MCP Environment Variable Denylist Bypass via Case SensitivityEPSS 1.3%CVE-2024-58351CRITICALFlowise - Remote Code Execution via overrideConfig ParameterEPSS 0.9%CVE-2025-71338CRITICALFlowise - Arbitrary File Write to Remote Code Execution via document-store APIEPSS 0.9%CVE-2025-71333CRITICALFlowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments EndpointEPSS 0.8%CVE-2025-71327CRITICALFlowise - Authentication Bypass via Unprotected Registration EndpointEPSS 0.6%CVE-2026-56270HIGHFlowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod EndpointEPSS 0.5%CVE-2026-56267MEDIUMFlowise - PII Disclosure via Unauthenticated Forgot Password EndpointEPSS 0.5%CVE-2025-71328HIGHFlowise - Unverified Password Change via Account SettingsEPSS 0.4%CVE-2026-56271CRITICALFlowise - Weak Default JWT Secrets in Authentication MiddlewareEPSS 0.4%CVE-2026-56278CRITICALFlowise - Session Hijacking via Weak Default Express Session SecretEPSS 0.4%CVE-2026-56276MEDIUMFlowise - Mass Assignment in PUT /api/v1/user Allows Password Hash OverrideEPSS 0.4%CVE-2025-71337HIGHFlowise - Unverified Email Change via Account Profile EndpointEPSS 0.4%CVE-2025-71332HIGHFlowise - SQL Injection in importChatflows API via chatflow.id ParameterEPSS 0.3%CVE-2026-56268MEDIUMFlowise - Cross-Workspace Information Disclosure via chatflows/apikey EndpointEPSS 0.3%CVE-2026-56273MEDIUMFlowise - Path Traversal in Vector Store basePath ParameterEPSS 0.3%CVE-2025-71335HIGHFlowise - Session Invalidation Failure After Password ChangeEPSS 0.3%