Skip to content
COOEY

FAIL › dossier

flowise

PRODUCT

· dossier confidence 40%

Flowise is a low-code AI app builder that was sunsetting in August 2026 after a series of critical unauthenticated RCE and file upload vulnerabilities were discovered in late 2025 and early 2026.

PROFILE
CategorySoftware ProductWhat they doFlowise is a low-code platform for building AI applications using visual workflows and drag-and-drop interfaces.HQSan Francisco, CA Websitehttps://flowiseai.com ↗
SECURITY POSTURE

Critical vulnerabilities including unauthenticated RCE and file upload exploits were discovered in late 2025 and early 2026, with no remediation timeline provided before the product's sunset.

Notable failures
  • CVE-2025-71338: Unauthenticated RCE via path traversal in document-store loader
  • CVE-2025-71333: Unauthenticated file upload via attachments endpoint
  • CVE-2026-42861: Critical vulnerability in drag-and-drop UI
  • CVE-2026-46440: Critical vulnerability in drag-and-drop UI
  • CVE-2026-46441: Critical vulnerability in drag-and-drop UI
  • CVE-2026-46442: Critical vulnerability in drag-and-drop UI
Patterns: Repeated critical unauthenticated RCEs in 2025-2026; File upload vulnerabilities in storage endpoints; Lack of patching before product sunset
FAILURE HISTORY · 7
DATEEVENTSEVSUMMARY
2026-06-25 CVE-2025-71338 critical Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fileName parameters with ../ sequences to overwrite critical f
2026-06-25 CVE-2025-71333 critical Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary director
2026-06-08 CVE-2026-42861 critical CVE-2026-42861: Flowise is a drag & drop user interface to build a customized large language mod
2026-06-08 CVE-2026-46440 critical CVE-2026-46440: Flowise is a drag & drop user interface to build a customized large language mod
2026-06-08 CVE-2026-46441 critical CVE-2026-46441: Flowise is a drag & drop user interface to build a customized large language mod
2026-06-08 CVE-2026-46442 critical CVE-2026-46442: Flowise is a drag & drop user interface to build a customized large language mod
2025-10-14 CVE-2025-34267 critical CVE-2025-34267: Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled c
Open questions: Exact founding date not explicitly stated in web evidence · Precise HQ location not confirmed in web evidence · Current status of CVE-2025-34267 patching timeline
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-30 03:48:09.551360+00:00