Flowise is officially being sunset and will soon cease active maintenance or support. As a result, we are no longer accepting new security vulnerability reports for this repository. You can find more information here.
Security: FlowiseAI/Flowise
Security
SECURITY.md
-
Unsandboxed RCE via Custom MCPGHSA-6933-jpx5-q87q published
Sep 13, 2025 by HenryHengZJHigh -
RCE via Dynamic function constructor injectionGHSA-hmgh-466j-fx4c published
Oct 3, 2025 by HenryHengZJCritical -
Stored XSS via "View Messages" allows credential theft in FlowiseAI admin panelGHSA-964p-j4gg-mhwc published
Oct 3, 2025 by HenryHengZJCritical -
Code Injection in CSVAgent leads to Authenticated RCEGHSA-9wc7-mj3f-74xv published
Apr 15, 2026 by igor-magun-wdCritical -
Authenticated users lead SQL injection to Flowise DB.GHSA-9c4c-g95m-c8cp published
Apr 7, 2025 by HenryHengZJModerate -
Flowise Pre-auth Arbitrary File UploadGHSA-h42x-xx2q-6v6g published
Mar 13, 2025 by HenryHengZJCritical -
Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.GHSA-f228-chmx-v6j6 published
Apr 15, 2026 by igor-magun-wdHigh -
Stored XSS through logs in chatbotGHSA-7r4h-vmj9-wg42 published
Oct 3, 2025 by HenryHengZJModerate -
OverrideConfig security vulnerabilityGHSA-5cph-wvm9-45gj published
Nov 21, 2024 by HenryHengZJHigh -
Arbitrary file write to RCEGHSA-8vvx-qvq9-5948 published
Mar 14, 2025 by HenryHengZJCritical
Learn more about advisories related to FlowiseAI/Flowise in the GitHub Advisory Database