Flowise is officially being sunset and will soon cease active maintenance or support. As a result, we are no longer accepting new security vulnerability reports for this repository. You can find more information here.
Security: FlowiseAI/Flowise
Security
SECURITY.md
-
RCE in FlowiseAI/FlowiseGHSA-3gcm-f6qx-ff7p published
Sep 13, 2025 by HenryHengZJCritical -
File Upload in FlowiseAI/FlowiseGHSA-35g6-rrw3-v6xc published
Oct 6, 2025 by HenryHengZJHigh -
Arbitrary File ReadGHSA-99pg-hqvx-r4gf published
Sep 13, 2025 by HenryHengZJCritical -
Critical Multi-Tenant Variable Disclosure in Flowise Cloud via Custom JavaScript FunctionGHSA-435c-mg9p-fv22 published
Sep 12, 2025 by HenryHengZJCritical -
FlowiseAI Pre-Auth Arbitrary Code ExecutionGHSA-7944-7c6r-55vv published
Sep 13, 2025 by HenryHengZJCritical -
XSS vulnerability in FlowiseGHSA-4fr9-3x69-36wv published
Oct 3, 2025 by HenryHengZJCritical -
Authentication Bypass Using Unprotected Registration Endpoint (/register)GHSA-v5w9-prxf-w882 published
Nov 15, 2025 by HenryHengZJCritical -
Authenticated Remote code execution (RCE) via Arbitrary File WriteGHSA-pr8x-mr56-fx5p published
Oct 8, 2025 by HenryHengZJCritical -
Flowise Authenticated Command Execution and Sandbox Bypass via Puppeteer and Playwright PackagesGHSA-5w3r-f6gm-c25w published
Oct 3, 2025 by HenryHengZJHigh -
Arbitrary file access due to missing chat flow id validationGHSA-q67q-549q-p849 published
Sep 13, 2025 by HenryHengZJCritical
Learn more about advisories related to FlowiseAI/Flowise in the GitHub Advisory Database