FlowiseAI Flowise
Published Atomicorp research notes for CVEs affecting FlowiseAI Flowise where WAF protections were observed during testing or engineering review.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
| CVE | Vulnerability | CVSS | Severity | Rules Observed |
|---|---|---|---|---|
| CVE-2025-59528 | Flowise - Remote Code Execution | 10.0 (v3.1) | Critical | 345240 , 380026 |
| CVE-2025-26319 | FlowiseAI Flowise <= 2.2.6 - Arbitrary File Upload | 9.8 (v3.1) | Critical | 346019 |
| CVE-2026-70477 | Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability | 9.5 (v4.0) | Critical | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-46442 | Flowise < 3.1.2 - node-custom-function Unauthorized RCE | 9.4 (v4.0) | Critical | 345240 |
| CVE-2026-69256 | Flowise: Remote Code Execution Vulnerability in CSVAgent | 9.4 (v4.0) | Critical | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-73483 | Flowise before 3.1.3 Sandbox Escape via Puppeteer | 9.4 (v4.0) | Critical | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2025-71334 | Flowise - Path Traversal | 9.3 (v4.0) | Critical | 340007 |
| CVE-2026-69251 | Flowise RCE via TypeORM DataSource | 9.0 (v4.0) | Critical | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-73485 | Flowise before 3.1.3 Remote Code Execution via Airtable Agent | 9.0 (v4.0) | Critical | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73486 | Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV | 9.0 (v4.0) | Critical | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73487 | Flowise before 3.1.3 Prompt Injection RCE via CSV Agent | 9.0 (v4.0) | Critical | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2025-71324 | Flowise - Path Traversal | 8.7 (v4.0) | High | 340007 |
| CVE-2026-69250 | Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration | 8.5 (v4.0) | High | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2024-36420 | Flowise 1.4.3 - Arbitrary File Read | 7.5 (v3.1) | High | 344360 , 390709 |
| CVE-2026-67620 | Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List | 6.3 (v4.0) | Medium | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |