Security Advisories for flowise in npm
High
1 day ago
Flowise has Authentication Bypass Using Unprotected Registration Endpoint (/register)
npm
flowise
High
about 1 month ago
Flowise: Authenticated Command Execution and Sandbox Bypass via Puppeteer and Playwright Packages
npm
flowise
High
about 1 month ago
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
npm
flowise-components, flowise
Critical
about 1 month ago
Flowise is vulnerable to arbitrary file write through its WriteFileTool
npm
flowise-components, flowise
Critical
about 1 month ago
Flowise vulnerable to RCE via Dynamic function constructor injection
npm
flowise
Critical
about 2 months ago
Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
npm
flowise
Critical
2 months ago
Flowise has arbitrary file access due to missing chat flow id validation
npm
flowise
High
2 months ago
FlowiseAI/Flowise has Server-Side Request Forgery (SSRF) vulnerability
npm
flowise
Critical
2 months ago
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
npm
flowise
Moderate
about 1 year ago
Flowise and Flowise Chat Embed vulnerable to Stored Cross-site Scripting
npm
flowise, flowise-embed