This repository was archived by the owner on Aug 13, 2026. It is now read-only.
Security: FlowiseAI/Flowise
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
CSV_Agent customReadCSV Code Injection Remote Code Execution VulnerabilityGHSA-4878-cqgq-j53v published
Jul 29, 2026 by igor-magun-wdCritical -
Flowise RCE via SQL Database Chain NodeGHSA-pwfj-wh95-7mwp published
Aug 31, 2026 by igor-magun-wdCritical -
`DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow typeGHSA-p5w8-m249-4r4v published
Jul 29, 2026 by igor-magun-wdHigh -
Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organizationGHSA-wp74-f5hh-5f3r published
Jul 29, 2026 by igor-magun-wdHigh -
Authenticated arbitrary file write in Flowise `S3 Directory` document loader via unsanitized S3 object keysGHSA-88pr-878c-24wf published
Jul 29, 2026 by igor-magun-wdHigh -
Prompt Injection to RCE and SSRF via CSV/Airtable Agent Python Validator Bypass in FlowiseGHSA-w7x8-q2gp-5cgg published
Jul 29, 2026 by igor-magun-wdCritical -
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCEGHSA-52fh-8v99-63c2 published
Jul 29, 2026 by igor-magun-wdCritical -
SSRF + LLM API key exfiltration via user-controlled basepath / baseUrl in 8 chat-model nodesGHSA-hx55-h48h-7rw9 published
Aug 31, 2026 by igor-magun-wdCritical -
IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpointGHSA-2364-jh4q-m9vm published
Jul 27, 2026 by igor-magun-wdModerate -
Flowise RCE via TypeORM DataSourceGHSA-g32j-mmxr-gfq5 published
Jul 29, 2026 by igor-magun-wdCritical