CVE Tools

Flowise-components

24 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Flowise-components, a product in the ai ml space. Use it to gauge the current risk picture and drill into individual advisories.

Flowise-components CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Flowise-components CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-041
2025-050
2025-060
2025-070
2025-080
2025-090
2025-102
2025-110
2025-120
2026-010
2026-020
2026-031
2026-0417
2026-051
2026-060
2026-070
2026-082
2026-090

Severity

How the 24 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical330%
  • High770%

Latest CVEs

The 15 most recently published vulnerabilities affecting Flowise-components.

  1. GHSA-88pr-878c-24wfFlowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys —
  2. CVE-2026-69251Flowise RCE via TypeORM DataSource8.8
  3. GHSA-m99r-2hxc-cp3qFlowise has an MCP Security Bypass that Enables RCE—
  4. CVE-2026-41274Flowise: Cypher Injection in GraphCypherQAChain9.8
  5. CVE-2026-41271Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains8.3
  6. CVE-2026-41272Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)7.1
  7. CVE-2026-41270Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox7.1
  8. CVE-2026-41137Flowise: Code Injection in CSVAgent leads to Authenticated RCE8.8
  9. CVE-2026-40933Flowise: Authenticated RCE Via MCP Adapters9.9
  10. GHSA-v38x-c887-992fFlowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability—
  11. GHSA-28g4-38q8-3cwcFlowise: Cypher Injection in GraphCypherQAChain—
  12. GHSA-6r77-hqx7-7vw8Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains—
  13. GHSA-2x8m-83vc-6wv4Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)—
  14. GHSA-xhmj-rg95-44hvFlowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox—
  15. GHSA-cvrr-qhgw-2mm6Flowise: Parameter Override Bypass Remote Command Execution—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store