Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-73604: Exposure of Sensitive Information to an Unauthorized Actor in FlowiseAI FlowiseCVE-2026-73604
0

Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive data including database connection URLs with embedded passwords, cloud service account JSON with private keys, and API keys by calling this endpoint.

Join the discussion
CVE-2026-73603: Missing Authorization in FlowiseAI FlowiseCVE-2026-73603
0

Flowise versions prior to 3.1.4 contain a vulnerability in the unauthenticated text-to-speech (TTS) endpoint where chatflow visibility is not properly validated. This allows unauthenticated attackers to misuse private chatflow TTS credentials by supplying a valid chatflow UUID. As a result, attackers can generate unlimited TTS audio using stored OpenAI or ElevenLabs API keys, potentially causing financial costs to the chatflow owner.

Join the discussion
CVE-2026-73487: Improper Control of Generation of Code ('Code Injection') in FlowiseAI FlowiseCVE-2026-73487
0

Flowise before version 3.1.3 contains a code injection vulnerability in its CSV and Airtable Agent nodes. This flaw allows unauthenticated attackers to bypass a regex-based Python code validator via prompt injection. Exploitation can lead to malicious code execution, including dataset exfiltration, SSRF attacks against internal services, or arbitrary code execution through the unauthenticated prediction API.

Join the discussion
CVE-2026-73486: Improper Control of Generation of Code ('Code Injection') in FlowiseAI FlowiseCVE-2026-73486
0

Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a static regex blocklist that can be bypassed through obfuscation techniques, enabling attackers to execute code in the unsandboxed pyodide environment with full system access.

Join the discussion
CVE-2026-73485: Improper Control of Generation of Code ('Code Injection') in FlowiseAI FlowiseCVE-2026-73485
0

Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques. Attackers can send crafted prompts to a chatflow using the Airtable Agent node to inject malicious Python code that executes in an unsandboxed pyodide environment with full access to the host operating system.

Join the discussion
CVE-2026-71962: Missing Authorization in FlowiseAI FlowiseCVE-2026-71962
0

Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attackers to access private files by exploiting the endpoint's inclusion in the global authentication whitelist, which bypasses all session and API key verification. Attackers can supply valid chatflowId, chatId, and fileName identifiers to retrieve files from any chatflow on the instance, including private chatflows belonging to other workspaces or organizations.

Join the discussion
CVE-2026-67620: Server-Side Request Forgery (SSRF) in FlowiseAI FlowiseCVE-2026-67620
0

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200, allowing authenticated attackers to force the server to issue arbitrary GET requests to cloud instance metadata services. Attackers can send requests to the fetch-links API endpoint with a crafted URL parameter, bypassing deny-list validation including redirect-based bypasses, to reach instance metadata services and expose instance identity data and role credentials on Oracle Cloud Infrastructure or Alibaba Cloud deployments, with unauthenticated access possible when URL-fetching nodes exist in public chatflows.

Join the discussion
CVE-2026-70636: Missing Authorization in FlowiseAI FlowiseCVE-2026-70636
0

Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can send a POST request to the oauth2-credential refresh route with a trailing credential identifier to bypass all authentication and authorization checks, triggering unauthorized OAuth token rotation against credentials belonging to any workspace and potentially disrupting dependent OAuth integrations. This is a bypass of CVE-2026-41273.

Join the discussion
CVE-2026-67622: Authorization Bypass Through User-Controlled Key in FlowiseAI FlowiseCVE-2026-67622
0

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification. Attackers can enumerate cross-workspace assistant metadata, retrieve file and vector store listings, and upload files into victim workspaces by exploiting the missing workspace-scoped authorization check in the credential lookup logic.

Join the discussion
CVE-2026-67621: Missing Authorization in FlowiseAI FlowiseCVE-2026-67621
0

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to trigger document ingestion, refresh vector database contents, consume embedding API credits, and modify knowledge bases used by downstream chatflows.

Join the discussion

Showing 1 to 10 of 31 results

Filters:Package: pkg:github/flowiseai/Flowise
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses