CVE-2026-30822

HIGH

Flowise <3.0.13 - Code Injection

Title source: llm
STIX 2.1

Description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauthenticated users can inject arbitrary values into internal database fields when creating leads. This issue has been patched in version 3.0.13.

Scores

CVSS v3 7.7
EPSS 0.0027
EPSS Percentile 49.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-915
Status published
Products (2)
flowiseai/flowise < 3.0.13
npm/flowise 0 - 3.0.13npm
Published Mar 07, 2026
Tracked Since Mar 07, 2026