Security Advisories for flowise in npm
High
18 days ago
Flowise: Authenticated Command Execution and Sandbox Bypass via Puppeteer and Playwright Packages
npm
flowise
High
22 days ago
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
npm
flowise-components, flowise
Critical
24 days ago
Flowise is vulnerable to arbitrary file write through its WriteFileTool
npm
flowise-components, flowise
Critical
27 days ago
Flowise vulnerable to RCE via Dynamic function constructor injection
npm
flowise
Critical
29 days ago
Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
npm
flowise
Critical
about 2 months ago
Flowise has arbitrary file access due to missing chat flow id validation
npm
flowise
High
about 2 months ago
FlowiseAI/Flowise has Server-Side Request Forgery (SSRF) vulnerability
npm
flowise
Critical
about 2 months ago
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
npm
flowise
Moderate
about 1 year ago
Flowise and Flowise Chat Embed vulnerable to Stored Cross-site Scripting
npm
flowise, flowise-embed
Moderate
about 1 year ago
Flowise Cross-site Scripting in /api/v1/chatflows-streaming/id
npm
flowise