Vulnerability Database

With exploit

flowiseai / flowise

Title Severity Exploit Date Affected Version
CVE-2025-29189 High Apr 9, 2025 <= 2.2.3
CVE-2025-26319 High Mar 5, 2025 == 2.2.6
CVE-2024-9148 Medium Sep 25, 2024 < 2.1.1
CVE-2024-8181 High Aug 27, 2024 == 1.8.2
CVE-2024-8182 High Aug 27, 2024 == 1.8.2
CVE-2024-37146 Medium Jul 1, 2024 <= 1.4.3
CVE-2024-37145 Medium Jul 1, 2024 <= 1.4.3
CVE-2024-36423 Medium Jul 1, 2024 <= 1.4.3
CVE-2024-36422 Medium Jul 1, 2024 == 1.4.3
CVE-2024-36421 High Jul 1, 2024 == 1.4.3

Node.js icon flowise

Title Severity Exploit Date Affected Version
CVE-2025-34267 High Oct 14, 2025 >= 3.0.1 < 3.0.8
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool High Oct 10, 2025 < 3.0.8
CVE-2025-61913 Critical Oct 9, 2025 < 3.0.8
CVE-2025-61687 High Oct 8, 2025 == 3.0.7
>= 3.0.7 < 3.0.8
CVE-2025-55346 Critical Oct 6, 2025 <= 2.2.7-patch.1
CVE-2025-29192 Medium Oct 3, 2025 < 3.0.5
CVE-2025-50538 Critical Oct 3, 2025 < 3.0.8
Flowise vulnerable to XSS Medium Oct 3, 2025 < 3.0.8
Flowise has unsandboxed remote code execution via Custom MCP High Sep 15, 2025 >= 2.2.7-patch.1 < 3.0.6
Flowise has arbitrary file access due to missing chat flow id validation Critical Sep 15, 2025 >= 2.2.8 < 3.0.6