Flowise is officially being sunset and will soon cease active maintenance or support. As a result, we are no longer accepting new security vulnerability reports for this repository. You can find more information here.
This repository was archived by the owner on Aug 13, 2026. It is now read-only.
Security: FlowiseAI/Flowise
Security
SECURITY.md
-
Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network AccessGHSA-fvcw-9w9r-pxc7 published
Mar 9, 2026 by igor-magun-wdHigh -
Arbitrary File Upload via MIME Spoofing in FlowiseAI/FlowiseGHSA-j8g8-j7fc-43v6 published
Mar 5, 2026 by igor-magun-wdHigh -
Flowise Authorization Bypass via Spoofed x-request-from HeaderGHSA-wvhq-wp8g-c7vq published
Mar 5, 2026 by igor-magun-wdHigh -
Failure to Invalidate Existing Sessions After Password ChangeGHSA-x7rp-qj2h-ghgw published
Nov 12, 2025 by HenryHengZJHigh -
Bypass of Password Confirmation - Unverified Email Change (credentials)GHSA-x39m-3393-3qp4 published
Nov 12, 2025 by HenryHengZJHigh -
Bypass of Password Confirmation - Unverified Password ChangeGHSA-fjh6-8679-9pch published
Nov 12, 2025 by HenryHengZJHigh -
WriteFileTool arbitrary file write vulnerabilityGHSA-jv9m-vf54-chjj published
Oct 8, 2025 by HenryHengZJCritical -
ReadFileTool arbitrary file read vulnerabilityGHSA-j44m-5v8f-gc9c published
Oct 8, 2025 by HenryHengZJHigh -
Critical: Unauthenticated Password Reset Token Disclosure Leading to Account Takeover in Flowise Cloud and Local DeploymentsGHSA-wgpv-6j63-x5ph published
Sep 12, 2025 by HenryHengZJCritical -
SSRF in FlowiseAI/FlosiseGHSA-hr92-4q35-4j3m published
Sep 13, 2025 by HenryHengZJHigh
Learn more about advisories related to FlowiseAI/Flowise in the GitHub Advisory Database