All verified exploits

CVE-2026-30821 File Upload with Forged MIME Type

Deterministic critical Flowise Added cve-verified-cve-2026-30821

Uploads a file with mismatched MIME type to the unauthenticated attachment endpoint, proving that Flowise accepts executable scripts disguised as harmless file types.

Is your app exploitable through CVE-2026-30821?

Scan your domain free