CVE-2026-30821General(flowiseai / flowise)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId/:chatId endpoint is listed in WHITELIST_URLS, allowing unauthenticated access to the file upload API. While the server validates uploads based on the MIME types defined in chatbotConfig.fullFileUpload.allowedUploadFileTypes, it implicitly trusts the client-provided Content-Type header (file.mimetype) without verifying the file's actual content (magic bytes) or extension (file.originalname). Consequently, an attacker can bypass this restriction by spoofing the Content-Type as a permitted type (e.g., application/pdf) while uploading malicious scripts or arbitrary files. Once uploaded via addArrayFilesToStorage, these files persist in backend storage (S3, GCS, or local disk). This vulnerability serves as a critical entry point that, when chained with other features like static hosting or file retrieval, can lead to Stored XSS, malicious file hosting, or Remote Code Execution (RCE). This issue has been patched in version 3.0.13.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-07); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-07: 1Mentions · 2026-03-12: 1Technical Details · 2026-03-12: 103-0703-12
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-071
General1
2026-03-121
Disclosure1
Full discourse2 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-30821 (CVSS:8.2, CRITICAL) is Analyzed. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /a..https://nvd.nist.gov/vuln/detail/CVE-2026-30821 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-30821 is identified as a critical vulnerability in Flowise before version 3.0.13 with CVSS 8.2, but no proof of concept, exploit, or mitigation details are provided.

    0000016
    172 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-30821 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId/:chatId endpoint… https://www.cve.org/CVERecord?id=CVE-2026-30821

    Post summary

    The post references CVE-2026-30821 in Flowise, mentioning a vulnerable API endpoint prior to version 3.0.13, but provides no further technical or exploit details.

    00000165
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more