A critical vulnerability (CVSS 9.8) in the on-premise version of Flowise allows a remote, anonymous attacker to bypass security controls. Affected versions include Open Source Flowise 3.0.1 and all versions prior to 3.0.11. A mitigation is available, and users should apply it or upgrade to version 3.0.11.
[WID-SEC-2025-2610] Flowise (on-premise): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 8.8 (hoch) Remoteangriff ja Datum 16.11.2025 Stand UPDATE 26.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Produktbeschreibung Flowise ist eine Benutzeroberfläche zur Erstellung von LLMs (Large Language Model). Produkte 16.11.2025 Open Source Flowise 3.0.1 Open Source Flowise <3.0.11 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Flowise ausnutzen, um Sicherheitsvorkehrungen zu umgehen. CVE Informationen Versionshistorie Feedback zum Advisory geben