TECHNOLOGIES: FLOWISE

Flowise Application Security Review

A Flowise chatflow is public to anyone with its ID as soon as it is built, before authentication or rate limiting apply. We test what that flow, its tools and credentials expose. CREST-certified testers, fixed price from £6,000 for a 5-day single-application scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Flowise Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Public

Flowise’s own documentation states that once a chatflow or agentflow is built, anyone with its ID can run it through the API or an embed, before any authentication or rate limit is added. Its documented fix for the resulting CORS error is to open CORS_ORIGINS and IFRAME_ORIGINS to every origin.

Why Flowise security comes down to what is public before you switch anything on

Flowise’s own documentation on chatflow-level access control is direct about what a freshly built flow allows: anyone who has the Chatflow ID can run it through the API or an embedded widget, with no authentication required unless you add it. The rate limit documentation makes the same point from the other side, warning that a chatflow shared publicly with no API authorisation is open to anybody, and offering a message-limit-per-duration control that has to be switched on for each flow rather than applying by default. We test which of your flows are reachable on the bare ID, and whether a rate limit is actually stopping repeated automated requests against them.

Authentication at the application level has moved on since Flowise’s early releases: its app-level authorisation guide describes a Passport.js login checking a bcrypt password hash and issuing short-lived JWT tokens in secure HTTP-only cookies, but the older single-account FLOWISE_USERNAME and FLOWISE_PASSWORD basic authentication is still documented, marked Deprecated rather than removed, so an instance upgraded from an older release can still be running it. Above that sits the workspace, where Flowise’s workspace documentation lets an Account Admin build custom roles with granular permissions, while reserving Roles, Users, Workspaces and Login Activity for the Account Admin alone, and its SSO configuration only lets an Organization Admin set up a provider, with every user invited in individually before they can sign in that way. We test what each role and every SSO invitation actually grants against what its holder needs.

The tool surface is where a Flowise agent stops being a chatbot and starts being able to act. Its Custom Tool documentation shows a JavaScript Function node importing built-in Node.js modules and external libraries to call a third-party API, code that can reach anything the server running Flowise allows it to, and its variables documentation lets a caller override a Runtime variable’s value per request through the prediction API, without touching the flow editor at all. Every model provider key and tool credential a flow depends on sits in Flowise’s own Credentials store, reused across chatflows rather than duplicated into each one. It is the same permission question we test on our wider AI and LLM penetration testing engagements, applied to Flowise’s own tools, variables and credentials.

SCOPE

What we pen test on a Flowise application

FL-01

Chatflow and Agentflow Public Access by Default

Flowise’s own documentation on chatflow-level access states that once a chatflow or agentflow is built, anyone who has the Chatflow ID can run it through the API or an embedded widget, with no authentication required unless it is added afterwards. We test which of your flows are reachable this way, and what data or tool a request against the bare ID can trigger.

FL-02

Rate Limiting as an Opt-In Setting

Flowise’s rate limit documentation is explicit that sharing a chatflow publicly with no API authorisation means anybody can access it, and the message-limit-per-duration control exists specifically to stop that being abused, but it has to be configured per chatflow rather than applying automatically. We test whether a public flow’s rate limit is set, and whether it actually stops repeated automated requests.

FL-03

App-Level Authentication: JWT, Cookies and Legacy Basic Auth

From v3.0.1 Flowise moved to a Passport.js-based login that checks a bcrypt password hash and issues short-lived JWT access and refresh tokens in secure HTTP-only cookies, but the older FLOWISE_USERNAME and FLOWISE_PASSWORD single-account basic authentication is still documented, marked Deprecated rather than removed. We test which authentication mode an instance actually runs, and whether a deployment upgraded from an older version is still carrying the deprecated setup.

FL-04

Workspace Roles and Custom Permissions

Flowise’s workspace documentation lets an Account Admin build custom roles with granular permissions over individual resources, but reserves the Roles, Users, Workspaces and Login Activity screens for the Account Admin alone, so a custom role can never grant that administrative reach even by accident. We test what every custom role in your workspace can actually see and do against what its holder needs.

FL-05

SSO Configuration and User Invitation

Flowise’s SSO is OIDC-based and only an Organization Admin can configure a provider such as Azure AD, and a user has to be invited into Flowise, keeping a record of their role and workspace, before they can sign in through SSO at all. We test who holds Organization Admin rights, how the invitation step is controlled, and whether a deprovisioned identity-provider account can still reach Flowise through a standing invitation.

FL-06

Runtime Variable Override via the Prediction API

Flowise distinguishes Static from Runtime variables and documents overriding a Runtime variable’s value per request by sending overrideConfig.vars in the prediction API call, without needing to open the flow’s editor. We test whether that override reaches values it should not, such as a prompt instruction or a downstream tool argument a variable was meant to fix in place.

FL-07

Credentials Store for Model and Tool Providers

Flowise introduced a dedicated Credentials store, separate from individual flow configuration, so that a model provider key or a tool’s API key is saved once and reused across chatflows rather than duplicated inside each one. We test who can create, view or reuse a saved credential, and whether a flow shared with a lower-privileged workspace member exposes the credential it depends on.

FL-08

Custom Tool JavaScript Function Nodes

Flowise’s Custom Tool documentation shows a JavaScript Function node importing built-in Node.js modules and external libraries such as node-fetch to call a third-party API from inside a flow, which means the node’s own code can reach anything that library or module allows on the server running Flowise. We test what a custom tool’s code can actually access beyond the API call its description names.

FL-09

CORS and Iframe Origins for Embedded Widgets

Flowise’s embed documentation addresses the CORS error a self-hosted deployment hits by default with the fix CORS_ORIGINS=* and IFRAME_ORIGINS=*, opening the prediction API and the iframe embed to every origin rather than the specific domain hosting the widget. We test what CORS_ORIGINS and IFRAME_ORIGINS are actually set to in your deployment against the domains that should be allowed to call it.

FL-10

Prompt Injection into Agentflow Tool Calls

An agentflow’s tools decide what Flowise can actually do once a model chooses to call them, and OWASP’s guidance on excessive agency in LLM applications is specific that a tool should be scoped to the minimum permissions its task needs. We test both direct and indirect prompt injection routes into an agentflow’s tool-calling decisions, in line with our wider AI and LLM penetration testing.

OUR PROCESS

Flowise Application Security Review: From Scope to Attestation

01

Scope and Access

We agree which chatflows, agentflows and workspaces are in scope, plus a login for at least one account per workspace role, any Chatflow IDs already shared publicly or embedded, and Organization Admin or Account Admin access where SSO or role configuration is in scope.

02

Access and Permission Mapping

We map every workspace role, SSO invitation, saved credential and public chatflow ID against who or what actually needs that level of access.

03

Manual Testing

A CREST-certified tester manually tests chatflow and agentflow exposure, authentication and rate limiting, custom tool code execution and variable overrides, and prompt injection into tool-calling decisions, chaining findings where they compound.

04

Attestation and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Flowise pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Flowise Application Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
CHATBOT / RAG
£6,000–£12,000
Depends on AI system complexity

Single LLM-powered chatbot, basic RAG (≤100 documents), no agent tools. Around 5 to 7 working days from kickoff to report.

Get a fixed quote
ENTERPRISE AI
£25,000+
Depends on AI system complexity

Production AI platform, multi-agent orchestration, regulated AI use case (FCA, NHS), custom-trained models. Around 12 to 18 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Flowise Application Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Flowise deployment?

We need a login for at least one account per workspace role in scope, from an ordinary editor through to Account Admin or Organization Admin where role and SSO configuration are being reviewed, plus the Chatflow IDs of any flows you have already made public or embedded. Read access to the Credentials store’s list of saved connections speeds up the review, though we do not need the underlying secret values themselves.

Will testing touch our live data?

We test the chatflows, agentflows and workspace you nominate, working against real roles, credentials and tool configuration rather than a copy, so we agree exclusions such as destructive tool calls, real payment actions or outbound emails before testing starts. We do not run untested prompts against production customer data without that agreement in writing.

How long does a Flowise application penetration test take?

A single Flowise deployment with one workspace and a limited set of chatflows sits in our 5-day single-application scope, with a report typically landing around 5 to 7 working days after kickoff. Multiple workspaces, a large agent tool set or several SSO-connected organisations moves into a wider AI penetration testing scope with more testing days.

Do you test self-hosted Flowise and Flowise Cloud the same way?

The underlying questions are the same: what a chatflow exposes by default, what each role and credential grants, and what a tool can reach. What differs is the boundary, since Flowise Cloud manages the hosting infrastructure itself, so we confirm during scoping exactly what you control on your plan and test to that boundary.

What is out of scope for a single-application Flowise test?

The underlying model provider’s own infrastructure, whether that is OpenAI, Anthropic, Google or a self-hosted model, is out of scope; we test how your Flowise deployment uses the model, not the provider’s platform. A separate agent, tool server or MCP server that sits outside this Flowise instance is scoped and quoted separately.

Do you need our custom tool source code?

No. Testing is black-box against the running application and its API by default. A grey-box option, where we review a Custom Tool node’s JavaScript Function code and the variables and credentials it references, is available if you want faster or deeper coverage of specific findings.

Does Flowise have a customer penetration-testing policy we need to follow?

Flowise is an open-source platform you deploy and control yourself when self-hosted, so there is no vendor notification process for the software itself. If you use Flowise Cloud or a connected model provider, we confirm that vendor’s current penetration-testing and acceptable-use terms during scoping before any testing begins.

Are your testers CREST certified?

Yes. Every Flowise engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Flowise application

A Flowise chatflow is public to anyone with its ID as soon as it is built, before authentication or rate limiting apply. We test what that flow, its tools and credentials expose. CREST-certified testers, fixed price from £6,000 for a 5-day single-application scope, quoted within 24 hours.