Flowise Application Security Review
A Flowise chatflow is public to anyone with its ID as soon as it is built, before authentication or rate limiting apply. We test what that flow, its tools and credentials expose. CREST-certified testers, fixed price from £6,000 for a 5-day single-application scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Flowise’s own documentation states that once a chatflow or agentflow is built, anyone with its ID can run it through the API or an embed, before any authentication or rate limit is added. Its documented fix for the resulting CORS error is to open CORS_ORIGINS and IFRAME_ORIGINS to every origin.
Why Flowise security comes down to what is public before you switch anything on
Flowise’s own documentation on chatflow-level access control is direct about what a freshly built flow allows: anyone who has the Chatflow ID can run it through the API or an embedded widget, with no authentication required unless you add it. The rate limit documentation makes the same point from the other side, warning that a chatflow shared publicly with no API authorisation is open to anybody, and offering a message-limit-per-duration control that has to be switched on for each flow rather than applying by default. We test which of your flows are reachable on the bare ID, and whether a rate limit is actually stopping repeated automated requests against them.
Authentication at the application level has moved on since Flowise’s early releases: its app-level authorisation guide describes a Passport.js login checking a bcrypt password hash and issuing short-lived JWT tokens in secure HTTP-only cookies, but the older single-account FLOWISE_USERNAME and FLOWISE_PASSWORD basic authentication is still documented, marked Deprecated rather than removed, so an instance upgraded from an older release can still be running it. Above that sits the workspace, where Flowise’s workspace documentation lets an Account Admin build custom roles with granular permissions, while reserving Roles, Users, Workspaces and Login Activity for the Account Admin alone, and its SSO configuration only lets an Organization Admin set up a provider, with every user invited in individually before they can sign in that way. We test what each role and every SSO invitation actually grants against what its holder needs.
The tool surface is where a Flowise agent stops being a chatbot and starts being able to act. Its Custom Tool documentation shows a JavaScript Function node importing built-in Node.js modules and external libraries to call a third-party API, code that can reach anything the server running Flowise allows it to, and its variables documentation lets a caller override a Runtime variable’s value per request through the prediction API, without touching the flow editor at all. Every model provider key and tool credential a flow depends on sits in Flowise’s own Credentials store, reused across chatflows rather than duplicated into each one. It is the same permission question we test on our wider AI and LLM penetration testing engagements, applied to Flowise’s own tools, variables and credentials.
SCOPE
What we pen test on a Flowise application
Chatflow and Agentflow Public Access by Default
Flowise’s own documentation on chatflow-level access states that once a chatflow or agentflow is built, anyone who has the Chatflow ID can run it through the API or an embedded widget, with no authentication required unless it is added afterwards. We test which of your flows are reachable this way, and what data or tool a request against the bare ID can trigger.
Rate Limiting as an Opt-In Setting
Flowise’s rate limit documentation is explicit that sharing a chatflow publicly with no API authorisation means anybody can access it, and the message-limit-per-duration control exists specifically to stop that being abused, but it has to be configured per chatflow rather than applying automatically. We test whether a public flow’s rate limit is set, and whether it actually stops repeated automated requests.
App-Level Authentication: JWT, Cookies and Legacy Basic Auth
From v3.0.1 Flowise moved to a Passport.js-based login that checks a bcrypt password hash and issues short-lived JWT access and refresh tokens in secure HTTP-only cookies, but the older FLOWISE_USERNAME and FLOWISE_PASSWORD single-account basic authentication is still documented, marked Deprecated rather than removed. We test which authentication mode an instance actually runs, and whether a deployment upgraded from an older version is still carrying the deprecated setup.
Workspace Roles and Custom Permissions
Flowise’s workspace documentation lets an Account Admin build custom roles with granular permissions over individual resources, but reserves the Roles, Users, Workspaces and Login Activity screens for the Account Admin alone, so a custom role can never grant that administrative reach even by accident. We test what every custom role in your workspace can actually see and do against what its holder needs.
SSO Configuration and User Invitation
Flowise’s SSO is OIDC-based and only an Organization Admin can configure a provider such as Azure AD, and a user has to be invited into Flowise, keeping a record of their role and workspace, before they can sign in through SSO at all. We test who holds Organization Admin rights, how the invitation step is controlled, and whether a deprovisioned identity-provider account can still reach Flowise through a standing invitation.
Runtime Variable Override via the Prediction API
Flowise distinguishes Static from Runtime variables and documents overriding a Runtime variable’s value per request by sending overrideConfig.vars in the prediction API call, without needing to open the flow’s editor. We test whether that override reaches values it should not, such as a prompt instruction or a downstream tool argument a variable was meant to fix in place.
Credentials Store for Model and Tool Providers
Flowise introduced a dedicated Credentials store, separate from individual flow configuration, so that a model provider key or a tool’s API key is saved once and reused across chatflows rather than duplicated inside each one. We test who can create, view or reuse a saved credential, and whether a flow shared with a lower-privileged workspace member exposes the credential it depends on.
Custom Tool JavaScript Function Nodes
Flowise’s Custom Tool documentation shows a JavaScript Function node importing built-in Node.js modules and external libraries such as node-fetch to call a third-party API from inside a flow, which means the node’s own code can reach anything that library or module allows on the server running Flowise. We test what a custom tool’s code can actually access beyond the API call its description names.
CORS and Iframe Origins for Embedded Widgets
Flowise’s embed documentation addresses the CORS error a self-hosted deployment hits by default with the fix CORS_ORIGINS=* and IFRAME_ORIGINS=*, opening the prediction API and the iframe embed to every origin rather than the specific domain hosting the widget. We test what CORS_ORIGINS and IFRAME_ORIGINS are actually set to in your deployment against the domains that should be allowed to call it.
Prompt Injection into Agentflow Tool Calls
An agentflow’s tools decide what Flowise can actually do once a model chooses to call them, and OWASP’s guidance on excessive agency in LLM applications is specific that a tool should be scoped to the minimum permissions its task needs. We test both direct and indirect prompt injection routes into an agentflow’s tool-calling decisions, in line with our wider AI and LLM penetration testing.
OUR PROCESS
Flowise Application Security Review: From Scope to Attestation
Scope and Access
We agree which chatflows, agentflows and workspaces are in scope, plus a login for at least one account per workspace role, any Chatflow IDs already shared publicly or embedded, and Organization Admin or Account Admin access where SSO or role configuration is in scope.
Access and Permission Mapping
We map every workspace role, SSO invitation, saved credential and public chatflow ID against who or what actually needs that level of access.
Manual Testing
A CREST-certified tester manually tests chatflow and agentflow exposure, authentication and rate limiting, custom tool code execution and variable overrides, and prompt injection into tool-calling decisions, chaining findings where they compound.
Attestation and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Flowise pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Flowise Application Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
Depends on AI system complexity
Single LLM-powered chatbot, basic RAG (≤100 documents), no agent tools. Around 5 to 7 working days from kickoff to report.
Get a fixed quoteDepends on AI system complexity
Multi-tool agent system, complex RAG pipeline, fine-tuned model, multi-tenant. Around 8 to 12 working days from kickoff to report.
Get a fixed quoteDepends on AI system complexity
Production AI platform, multi-agent orchestration, regulated AI use case (FCA, NHS), custom-trained models. Around 12 to 18 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Flowise For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Flowise Application Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Flowise deployment?
We need a login for at least one account per workspace role in scope, from an ordinary editor through to Account Admin or Organization Admin where role and SSO configuration are being reviewed, plus the Chatflow IDs of any flows you have already made public or embedded. Read access to the Credentials store’s list of saved connections speeds up the review, though we do not need the underlying secret values themselves.
Will testing touch our live data?
We test the chatflows, agentflows and workspace you nominate, working against real roles, credentials and tool configuration rather than a copy, so we agree exclusions such as destructive tool calls, real payment actions or outbound emails before testing starts. We do not run untested prompts against production customer data without that agreement in writing.
How long does a Flowise application penetration test take?
A single Flowise deployment with one workspace and a limited set of chatflows sits in our 5-day single-application scope, with a report typically landing around 5 to 7 working days after kickoff. Multiple workspaces, a large agent tool set or several SSO-connected organisations moves into a wider AI penetration testing scope with more testing days.
Do you test self-hosted Flowise and Flowise Cloud the same way?
The underlying questions are the same: what a chatflow exposes by default, what each role and credential grants, and what a tool can reach. What differs is the boundary, since Flowise Cloud manages the hosting infrastructure itself, so we confirm during scoping exactly what you control on your plan and test to that boundary.
What is out of scope for a single-application Flowise test?
The underlying model provider’s own infrastructure, whether that is OpenAI, Anthropic, Google or a self-hosted model, is out of scope; we test how your Flowise deployment uses the model, not the provider’s platform. A separate agent, tool server or MCP server that sits outside this Flowise instance is scoped and quoted separately.
Do you need our custom tool source code?
No. Testing is black-box against the running application and its API by default. A grey-box option, where we review a Custom Tool node’s JavaScript Function code and the variables and credentials it references, is available if you want faster or deeper coverage of specific findings.
Does Flowise have a customer penetration-testing policy we need to follow?
Flowise is an open-source platform you deploy and control yourself when self-hosted, so there is no vendor notification process for the software itself. If you use Flowise Cloud or a connected model provider, we confirm that vendor’s current penetration-testing and acceptable-use terms during scoping before any testing begins.
Are your testers CREST certified?
Yes. Every Flowise engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Flowise application
A Flowise chatflow is public to anyone with its ID as soon as it is built, before authentication or rate limiting apply. We test what that flow, its tools and credentials expose. CREST-certified testers, fixed price from £6,000 for a 5-day single-application scope, quoted within 24 hours.



