FAIL › dossier
flowiseai
VENDOR· dossier confidence 40%
Flowise is an open-source low-code AI app builder that is being sunset as of July 2026. The vendor has a critical security track record with multiple unauthenticated RCE and file upload vulnerabilities discovered in 2025-2026.
PROFILE
CategorySoftware VendorWhat they doFlowise is an open-source low-code platform for building AI applications using visual workflows and drag-and-drop interfaces. The project is being sunset as of July 2026 due to a shift toward AI coding agents.OwnershipOpen Source
Websitehttps://flowiseai.com ↗
SECURITY POSTURE
Critical vulnerabilities including unauthenticated RCE and file upload exploits were discovered in late 2025 and early 2026, with multiple CVEs published within a single week in June 2026.
Notable failures
- CVE-2025-71338: Unauthenticated RCE via path traversal in document-store loader
- CVE-2025-71333: Unauthenticated arbitrary file upload via attachments endpoint
- CVE-2026-42861: Critical vulnerability in drag-and-drop LLM interface
- CVE-2026-46440: Critical vulnerability in drag-and-drop LLM interface
- CVE-2026-46441: Critical vulnerability in drag-and-drop LLM interface
- CVE-2026-46442: Critical vulnerability in drag-and-drop LLM interface
Patterns: Repeated critical unauthenticated RCEs in 2025-2026; Multiple critical CVEs published within a single week; Vulnerabilities in document storage and attachment endpoints
FAILURE HISTORY · 7
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-06-25 | CVE-2025-71338 | critical | Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fileName parameters with ../ sequences to overwrite critical f |
| 2026-06-25 | CVE-2025-71333 | critical | Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary director |
| 2026-06-08 | CVE-2026-42861 | critical | CVE-2026-42861: Flowise is a drag & drop user interface to build a customized large language mod |
| 2026-06-08 | CVE-2026-46440 | critical | CVE-2026-46440: Flowise is a drag & drop user interface to build a customized large language mod |
| 2026-06-08 | CVE-2026-46441 | critical | CVE-2026-46441: Flowise is a drag & drop user interface to build a customized large language mod |
| 2026-06-08 | CVE-2026-46442 | critical | CVE-2026-46442: Flowise is a drag & drop user interface to build a customized large language mod |
| 2025-10-14 | CVE-2025-34267 | critical | CVE-2025-34267: Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled c |
DOSSIER SOURCES
- The Future of Flowise · flowiseai.com
- Companies in HARYANA - Indian Company & Director Details · www.companydetails.in
- Latest Registered Companies - CompanyDetails.in · www.companydetails.in
Open questions: No web sources provided to verify company details · No web sources provided to verify company details
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-30 03:49:40.525106+00:00