CVE-2026-30822
high · 7.7Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauthenticated users can inject arbitrary values into internal database fields when creating leads. This issue has been patched in version 3.0.13.
7.7
CVSS
12.9%
EPSS (exploit prob.)
96th
EPSS percentile
2026-03-07
Published
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Weaknesses
CWE-915
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| flowiseai | flowise | < 3.0.13 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-30822