FlowiseAI Flowise

Published Atomicorp research notes for CVEs affecting FlowiseAI Flowise where WAF protections were observed during testing or engineering review.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

CVEVulnerabilityCVSSSeverityRules Observed
CVE-2025-59528Flowise - Remote Code Execution10.0 (v3.1)Critical345240 , 380026
CVE-2025-26319FlowiseAI Flowise <= 2.2.6 - Arbitrary File Upload9.8 (v3.1)Critical346019
CVE-2026-70477Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability9.5 (v4.0)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-46442Flowise < 3.1.2 - node-custom-function Unauthorized RCE9.4 (v4.0)Critical345240
CVE-2026-69256Flowise: Remote Code Execution Vulnerability in CSVAgent9.4 (v4.0)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-73483Flowise before 3.1.3 Sandbox Escape via Puppeteer9.4 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2025-71334Flowise - Path Traversal9.3 (v4.0)Critical340007
CVE-2026-69251Flowise RCE via TypeORM DataSource9.0 (v4.0)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-73485Flowise before 3.1.3 Remote Code Execution via Airtable Agent9.0 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73486Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV9.0 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73487Flowise before 3.1.3 Prompt Injection RCE via CSV Agent9.0 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2025-71324Flowise - Path Traversal8.7 (v4.0)High340007
CVE-2026-69250Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration8.5 (v4.0)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2024-36420Flowise 1.4.3 - Arbitrary File Read7.5 (v3.1)High344360 , 390709
CVE-2026-67620Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List6.3 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022