A high-severity vulnerability (CVSS 7.7) in the Flowise LLM UI allows an authenticated remote attacker to bypass security controls. The article notes no mitigation is currently available and that Linux/UNIX systems running the open-source Flowise product are affected, but it does not specify the vulnerable version ranges, a fixed version, or a workaround.
[WID-SEC-2026-2719] Flowise: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen CVSS Base Score 7.7 (hoch) CVSS Temporal Score 7.3 (hoch) Remoteangriff ja Datum 09.08.2026 Stand 10.08.2026 Mitigation nein Betroffene Systeme Betriebssystem Linux UNIX Produktbeschreibung Flowise ist eine Benutzeroberfläche zur Erstellung von LLMs (Large Language Model). Produkte 09.08.2026 Open Source Flowise Angriff Angriff Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Flowise ausnutzen, um Sicherheitsvorkehrungen zu umgehen. CVE Informationen Versionshistorie Feedback zum Advisory geben