This repository was archived by the owner on Aug 13, 2026. It is now read-only.
Security: FlowiseAI/Flowise
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Flowise RCE via Custom MCP Config NodeGHSA-g98q-rm45-q9h8 published
Jul 29, 2026 by igor-magun-wdCritical -
Cross-workspace credential IDOR in openai-assistants-vector-storeGHSA-chm3-vqcf-52rx published
Jul 29, 2026 by igor-magun-wdHigh -
Script injection in Docker image build workflows allows secret theftGHSA-jrcq-qjw5-xx5q published
Aug 31, 2026 by igor-magun-wdHigh -
Cross-Workspace OAuth2 Credential Metadata LeakGHSA-wch5-xp77-fxg4 published
Jul 29, 2026 by igor-magun-wdHigh -
Flowise Sandbox Escape to RCEGHSA-wg86-r78f-74mp published
Jul 29, 2026 by igor-magun-wdCritical -
Remote Code Execution Vulnerability in CSVAgentGHSA-x6vm-w76m-8j7g published
Jul 29, 2026 by igor-magun-wdCritical -
Flowise vm2 Sandbox Escape to RCEGHSA-rqh4-rxw3-93rp published
Jul 29, 2026 by igor-magun-wdCritical -
SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in FlowiseGHSA-c6xh-wv4j-ppv5 published
Jul 29, 2026 by igor-magun-wdHigh -
RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions OverrideGHSA-3769-jgqc-cxm7 published
Jul 29, 2026 by igor-magun-wdCritical -
Cross-Session Data Leakage via NoSQL Injection in MongoDBMemory NodeGHSA-wpvf-4vfx-rgxm published
Aug 31, 2026 by igor-magun-wdHigh