This repository was archived by the owner on Aug 13, 2026. It is now read-only.
Security: FlowiseAI/Flowise
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
CustomTemplate create+update mass-assignment allows cross-workspace template takeoverGHSA-728h-4mwj-f2p4 published
May 14, 2026 by igor-magun-wdHigh -
Assistant create+update mass-assignment allows cross-workspace assistant takeoverGHSA-78pr-c5x5-jggc published
May 14, 2026 by igor-magun-wdHigh -
Cross-workspace credential IDOR in node-load-method allows low-privilege users to enumerate victim third-party resourcesGHSA-hqvm-7539-v83j published
Aug 28, 2026 by igor-magun-wdModerate -
Flowise Custom MCP npx package execution leads to authenticated server-side command executionGHSA-vcwp-f9rq-3887 published
Aug 31, 2026 by igor-magun-wdCritical -
Rce viaCSVAgent csvFile data URI base64 segment is interpolated into Python source without validation,GHSA-4j8x-x6v7-w9rq published
Jul 29, 2026 by igor-magun-wdCritical -
Flowise RCE via SQLite Record Manager NodeGHSA-x3hf-7cj6-3r4m published
Jul 29, 2026 by igor-magun-wdCritical -
Flowise MCP Server Config cwd Parameter Validation BypassGHSA-x7x8-95gh-42xm published
Aug 31, 2026 by igor-magun-wdCritical -
CSV Agent Prompt Injection Remote Code Execution VulnerabilityGHSA-5xvg-pmgg-3mxr published
Jul 29, 2026 by igor-magun-wdCritical -
openai-realtime endpoints allow cross-workspace tool disclosure and execution via unscoped chatflow IDGHSA-gggp-6qmf-xwwc published
Aug 31, 2026 by igor-magun-wdHigh -
Airtable_Agent Code Injection Remote Code Execution VulnerabilityGHSA-c5hr-rc98-xp3g published
Jul 29, 2026 by igor-magun-wdCritical