FAIL › dossier
flowise
PRODUCT· dossier confidence 40%
Flowise is a low-code AI app builder that was sunsetting in August 2026 after a series of critical unauthenticated RCE and file upload vulnerabilities were discovered in late 2025 and early 2026.
PROFILE
CategorySoftware ProductWhat they doFlowise is a low-code platform for building AI applications using visual workflows and drag-and-drop interfaces.HQSan Francisco, CA
Websitehttps://flowiseai.com ↗
SECURITY POSTURE
Critical vulnerabilities including unauthenticated RCE and file upload exploits were discovered in late 2025 and early 2026, with no remediation timeline provided before the product's sunset.
Notable failures
- CVE-2025-71338: Unauthenticated RCE via path traversal in document-store loader
- CVE-2025-71333: Unauthenticated file upload via attachments endpoint
- CVE-2026-42861: Critical vulnerability in drag-and-drop UI
- CVE-2026-46440: Critical vulnerability in drag-and-drop UI
- CVE-2026-46441: Critical vulnerability in drag-and-drop UI
- CVE-2026-46442: Critical vulnerability in drag-and-drop UI
Patterns: Repeated critical unauthenticated RCEs in 2025-2026; File upload vulnerabilities in storage endpoints; Lack of patching before product sunset
FAILURE HISTORY · 7
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-06-25 | CVE-2025-71338 | critical | Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fileName parameters with ../ sequences to overwrite critical f |
| 2026-06-25 | CVE-2025-71333 | critical | Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary director |
| 2026-06-08 | CVE-2026-42861 | critical | CVE-2026-42861: Flowise is a drag & drop user interface to build a customized large language mod |
| 2026-06-08 | CVE-2026-46440 | critical | CVE-2026-46440: Flowise is a drag & drop user interface to build a customized large language mod |
| 2026-06-08 | CVE-2026-46441 | critical | CVE-2026-46441: Flowise is a drag & drop user interface to build a customized large language mod |
| 2026-06-08 | CVE-2026-46442 | critical | CVE-2026-46442: Flowise is a drag & drop user interface to build a customized large language mod |
| 2025-10-14 | CVE-2025-34267 | critical | CVE-2025-34267: Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled c |
DOSSIER SOURCES
- The Future of Flowise · flowiseai.com
- End of Life for Flowise AI - AUG 2026 - LinkedIn · www.linkedin.com
- Profile - CRDO - NASDAQ - Weiss Ratings · weissratings.com
- Company Database Search · www.edgarcompany.sec.gov
- Audit Evidence Documentation: What Auditors Need · compliancestack.ai
- Time.is - exact time, any time zone · time.is
- World Clock — current time around the world · 24timezones.com
Open questions: Exact founding date not explicitly stated in web evidence · Precise HQ location not confirmed in web evidence · Current status of CVE-2025-34267 patching timeline
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-30 03:48:09.551360+00:00