Flowise is officially being sunset and will soon cease active maintenance or support. As a result, we are no longer accepting new security vulnerability reports for this repository. You can find more information here.
Security: FlowiseAI/Flowise
Security
SECURITY.md
-
Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via ChromiumGHSA-9gvv-qjj3-2p6g published
Jul 29, 2026 by igor-magun-wdCritical -
Authenticated Sandbox Escape and Data Exfiltration via Pandas Methods Bypass in pythonCodeValidatorGHSA-x58f-9m57-qc4m published
Jul 29, 2026 by igor-magun-wdHigh -
CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell VerifiedGHSA-vmv7-4m6c-3cg5 published
Jul 29, 2026 by igor-magun-wdCritical -
Evaluator create+update mass-assignment allows cross-workspace evaluator takeoverGHSA-wxrr-jp8m-qq7f published
May 14, 2026 by igor-magun-wdHigh -
Evaluation create+update mass-assignment allows cross-workspace evaluation takeoverGHSA-mq53-pc65-wjc4 published
May 14, 2026 by igor-magun-wdHigh -
Dataset create+update mass-assignment allows cross-workspace dataset takeoverGHSA-5h9v-837x-m97r published
May 14, 2026 by igor-magun-wdHigh -
DatasetRow create+update mass-assignment allows cross-workspace row takeoverGHSA-7j65-65cr-6644 published
May 14, 2026 by igor-magun-wdHigh -
CustomTemplate create+update mass-assignment allows cross-workspace template takeoverGHSA-728h-4mwj-f2p4 published
May 14, 2026 by igor-magun-wdHigh -
Assistant create+update mass-assignment allows cross-workspace assistant takeoverGHSA-78pr-c5x5-jggc published
May 14, 2026 by igor-magun-wdHigh -
Rce viaCSVAgent csvFile data URI base64 segment is interpolated into Python source without validation,GHSA-4j8x-x6v7-w9rq published
Jul 29, 2026 by igor-magun-wdCritical
Learn more about advisories related to FlowiseAI/Flowise in the GitHub Advisory Database