Security Advisories for Flowise in npm
Critical
10 days ago
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
npm
flowise
Critical
10 days ago
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
npm
flowise-components, flowise
High
10 days ago
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
npm
flowise
Moderate
10 days ago
Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
npm
flowise
High
10 days ago
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
npm
flowise
High
10 days ago
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
npm
flowise
Critical
10 days ago
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
npm
flowise-components, flowise
High
10 days ago
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
npm
flowise, flowise-components
High
10 days ago
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
npm
flowise
Critical
10 days ago
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
npm
flowise-components, flowise
High
10 days ago
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
npm
flowise-components, flowise
Critical
10 days ago
Flowise: Remote Code Execution Vulnerability in CSVAgent
npm
flowise, flowise-components
Critical
10 days ago
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
npm
flowise-components, flowise
Critical
10 days ago
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
npm
flowise-components, flowise
High
10 days ago
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
npm
flowise
Moderate
10 days ago
Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
npm
flowise
Moderate
3 months ago
Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows
npm
flowise
Moderate
3 months ago
Flowise: Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpage
npm
flowise
High
3 months ago
FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover
npm
flowise
High
3 months ago
FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover
npm
flowise
High
3 months ago
FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover
npm
flowise
High
3 months ago
FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover
npm
flowise
High
3 months ago
FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover
npm
flowise
High
3 months ago
FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover
npm
flowise
Critical
3 months ago
FlowiseAI: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
npm
flowise
High
3 months ago
FlowiseAI has Mass Assignment in Assistant Update Endpoint that Allows Cross-Workspace Resource Reassignment
npm
flowise
High
3 months ago
Flowise has an MCP Security Bypass that Enables RCE
npm
flowise-components, flowise
High
3 months ago
FlowiseAI has Mass Assignment in Chatflow Update Endpoint that Allows Cross-Workspace AgentFlow Reassignment
npm
flowise
High
3 months ago
FlowiseAI has Mass Assignment in Tool Update Endpoint that Allows Cross-Workspace Resource Reassignment
npm
flowise
High
3 months ago
FlowiseAI has Mass Assignment in Variable Update Endpoint that Allows Cross-Workspace Resource Reassignment
npm
flowise
Critical
4 months ago
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
npm
flowise-components, flowise
Critical
4 months ago
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
npm
flowise-components, flowise
High
4 months ago
Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials
npm
flowise
High
4 months ago
Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
npm
flowise
High
4 months ago
Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow in Flowise
npm
flowise
High
4 months ago
Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains
npm
flowise-components, flowise
High
4 months ago
Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)
npm
flowise-components, flowise
High
4 months ago
Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
npm
flowise-components, flowise
High
4 months ago
Flowise: Parameter Override Bypass Remote Command Execution
npm
flowise-components, flowise
High
4 months ago
Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association
npm
flowise
Critical
4 months ago
Flowise: Code Injection in CSVAgent leads to Authenticated RCE
npm
flowise-components, flowise
High
4 months ago
Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.
npm
flowise-components, flowise
Moderate
4 months ago
Flowise Execute Flow function has an SSRF vulnerability
npm
flowise-components, flowise
Moderate
4 months ago
Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)
npm
flowise-components, flowise
Moderate
4 months ago
Flowise: Path Traversal in Vector Store basePath
npm
flowise-components, flowise
Moderate
4 months ago
Flowise: Unauthenticated Information Disclosure of OAuth Secrets (Cleartext) via GET Request
npm
flowise
High
5 months ago
Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access
npm
flowise
High
5 months ago
Flowise has IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration
npm
flowise
Moderate
5 months ago
Flowise Vulnerable to PII Disclosure on Unauthenticated Forgot Password Endpoint
npm
flowise
High
9 months ago
Flowise has Authentication Bypass Using Unprotected Registration Endpoint (/register)
npm
flowise
High
10 months ago
Flowise: Authenticated Command Execution and Sandbox Bypass via Puppeteer and Playwright Packages
npm
flowise
High
10 months ago
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
npm
flowise-components, flowise
Critical
10 months ago
Flowise is vulnerable to arbitrary file write through its WriteFileTool
npm
flowise-components, flowise
Critical
10 months ago
Flowise vulnerable to RCE via Dynamic function constructor injection
npm
flowise
Critical
10 months ago
Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
npm
flowise
Critical
11 months ago
Flowise has arbitrary file access due to missing chat flow id validation
npm
flowise
High
11 months ago
FlowiseAI/Flowise has Server-Side Request Forgery (SSRF) vulnerability
npm
flowise
Critical
11 months ago
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
npm
flowise