Skip to content
COOEY

FAIL › dossier

flowiseai

VENDOR

· dossier confidence 40%

Flowise is an open-source low-code AI app builder that is being sunset as of July 2026. The vendor has a critical security track record with multiple unauthenticated RCE and file upload vulnerabilities discovered in 2025-2026.

PROFILE
CategorySoftware VendorWhat they doFlowise is an open-source low-code platform for building AI applications using visual workflows and drag-and-drop interfaces. The project is being sunset as of July 2026 due to a shift toward AI coding agents.OwnershipOpen Source Websitehttps://flowiseai.com ↗
SECURITY POSTURE

Critical vulnerabilities including unauthenticated RCE and file upload exploits were discovered in late 2025 and early 2026, with multiple CVEs published within a single week in June 2026.

Notable failures
  • CVE-2025-71338: Unauthenticated RCE via path traversal in document-store loader
  • CVE-2025-71333: Unauthenticated arbitrary file upload via attachments endpoint
  • CVE-2026-42861: Critical vulnerability in drag-and-drop LLM interface
  • CVE-2026-46440: Critical vulnerability in drag-and-drop LLM interface
  • CVE-2026-46441: Critical vulnerability in drag-and-drop LLM interface
  • CVE-2026-46442: Critical vulnerability in drag-and-drop LLM interface
Patterns: Repeated critical unauthenticated RCEs in 2025-2026; Multiple critical CVEs published within a single week; Vulnerabilities in document storage and attachment endpoints
FAILURE HISTORY · 7
DATEEVENTSEVSUMMARY
2026-06-25 CVE-2025-71338 critical Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fileName parameters with ../ sequences to overwrite critical f
2026-06-25 CVE-2025-71333 critical Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary director
2026-06-08 CVE-2026-42861 critical CVE-2026-42861: Flowise is a drag & drop user interface to build a customized large language mod
2026-06-08 CVE-2026-46440 critical CVE-2026-46440: Flowise is a drag & drop user interface to build a customized large language mod
2026-06-08 CVE-2026-46441 critical CVE-2026-46441: Flowise is a drag & drop user interface to build a customized large language mod
2026-06-08 CVE-2026-46442 critical CVE-2026-46442: Flowise is a drag & drop user interface to build a customized large language mod
2025-10-14 CVE-2025-34267 critical CVE-2025-34267: Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled c
Open questions: No web sources provided to verify company details · No web sources provided to verify company details
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-30 03:49:40.525106+00:00