npm package intelligence
flowise Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting the npm package flowise, including the gap beyond CISA KEV, confidence assessments, and sensor observations.
- Total KEVs
- 7
- Known exploited vulnerabilities affecting flowise
- In CISA KEV
- 0
- Records also listed in the official catalog
- Beyond CISA KEV
- 7
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 6
- flowise KEVs with sensor-observed exploitation activity
Review flowise exploitation against the versions you run
Seven of the seven exploited flowise vulnerabilities tracked here are not in CISA KEV.
- 0%
- Covered by CISA
- 100%
- Beyond CISA
Attested flowise vulnerabilities
7 known exploited vulnerabilities affecting this package.
| Vulnerability | CISA KEV | Added |
|---|---|---|
|
CVE-2026-56270
Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint |
Beyond CISA | 17 Aug 2026 |
|
CVE-2025-8943
Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers |
Beyond CISA | 05 Aug 2026 |
|
CVE-2024-36420
GHSL-2023-232: Flowise Path Injection at /api/v1/openai-assistants-file |
Beyond CISA | 17 Jul 2026 |
|
CVE-2026-46442
Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape |
Beyond CISA | 17 Jul 2026 |
|
CVE-2025-55346
Unintended dynamic code execution leads to remote code execution by network attackers |
Beyond CISA | 01 Jun 2026 |
|
CVE-2024-8181
Flowise Authentication Bypass |
Beyond CISA | 30 Jul 2025 |
|
CVE-2025-26319
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments. |
Beyond CISA | 24 Jun 2025 |
Recurring weakness patterns
Missing Authentication for Critical Function, Improper Control of Generation of Code ('Code Injection'), and Improper Authentication account for mapped occurrences across this flowise KEV portfolio.
CWE-306
Missing Authentication for Critical Function
CWE-94
Improper Control of Generation of Code ('Code Injection')
CWE-287
Improper Authentication
CWE-434
Unrestricted Upload of File with Dangerous Type
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-862
Missing Authorization