CPE
Authorization Bypass in Flowise openai-realtime Endpoints
1 CVEFlowise versions prior to 3.1.4 contain an authorization flaw in the openai-realtime endpoint, enabling authenticated users to access and execute tools in unauthorized workspaces via cross-workspace ID manipulation.
Unauthenticated Account Takeover in Flowise via CVE-2025-58434
1 rule 1 TTP 1 CVECVE-2025-58434 is a critical vulnerability in Flowise versions prior to 3.0.6 where the password reset API leaks a temporary token, enabling unauthenticated account takeover.
Flowise Unauthenticated RCE via Environment Variable Bypass
6 rules 11 TTPs 8 CVEs 2 IOCsFlowise v3.1.2 and earlier are vulnerable to unauthenticated remote code execution because the CVE-2025-8943 patch relies on an incomplete environment variable blocklist, allowing attackers to inject configuration variables that force arbitrary package installation.
FlowiseAI Flowise CSV Agent Prompt Injection RCE Vulnerability
2 rules 1 TTP 4 CVEsA remote code execution vulnerability exists in FlowiseAI Flowise version 3.0.13 due to insufficient sandboxing when evaluating LLM-generated Python scripts, allowing unauthenticated attackers to inject malicious code via prompts processed by the CSV Agent node, bypassing input validation, to execute arbitrary OS commands.