Flowise is officially being sunset and will soon cease active maintenance or support. As a result, we are no longer accepting new security vulnerability reports for this repository. You can find more information here.
This repository was archived by the owner on Aug 13, 2026. It is now read-only.
Security: FlowiseAI/Flowise
Security
SECURITY.md
-
Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via ChromiumGHSA-9gvv-qjj3-2p6g published
Jul 29, 2026 by igor-magun-wdCritical -
Authenticated Sandbox Escape and Data Exfiltration via Pandas Methods Bypass in pythonCodeValidatorGHSA-x58f-9m57-qc4m published
Jul 29, 2026 by igor-magun-wdHigh -
CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell VerifiedGHSA-vmv7-4m6c-3cg5 published
Jul 29, 2026 by igor-magun-wdCritical -
Evaluator create+update mass-assignment allows cross-workspace evaluator takeoverGHSA-wxrr-jp8m-qq7f published
May 14, 2026 by igor-magun-wdHigh -
Evaluation create+update mass-assignment allows cross-workspace evaluation takeoverGHSA-mq53-pc65-wjc4 published
May 14, 2026 by igor-magun-wdHigh -
Dataset create+update mass-assignment allows cross-workspace dataset takeoverGHSA-5h9v-837x-m97r published
May 14, 2026 by igor-magun-wdHigh -
DatasetRow create+update mass-assignment allows cross-workspace row takeoverGHSA-7j65-65cr-6644 published
May 14, 2026 by igor-magun-wdHigh -
CustomTemplate create+update mass-assignment allows cross-workspace template takeoverGHSA-728h-4mwj-f2p4 published
May 14, 2026 by igor-magun-wdHigh -
Assistant create+update mass-assignment allows cross-workspace assistant takeoverGHSA-78pr-c5x5-jggc published
May 14, 2026 by igor-magun-wdHigh -
Rce viaCSVAgent csvFile data URI base64 segment is interpolated into Python source without validation,GHSA-4j8x-x6v7-w9rq published
Jul 29, 2026 by igor-magun-wdCritical
Learn more about advisories related to FlowiseAI/Flowise in the GitHub Advisory Database