Security Advisories for flowise-components in npm
Critical
8 days ago
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
npm
flowise-components, flowise
Critical
8 days ago
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
npm
flowise-components, flowise
High
8 days ago
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
npm
flowise, flowise-components
Critical
8 days ago
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
npm
flowise-components, flowise
High
8 days ago
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
npm
flowise-components, flowise
Critical
8 days ago
Flowise: Remote Code Execution Vulnerability in CSVAgent
npm
flowise, flowise-components
Critical
8 days ago
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
npm
flowise-components, flowise
Critical
8 days ago
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
npm
flowise-components, flowise
High
3 months ago
Flowise has an MCP Security Bypass that Enables RCE
npm
flowise-components, flowise
Critical
4 months ago
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
npm
flowise-components, flowise
Critical
4 months ago
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
npm
flowise-components, flowise
High
4 months ago
Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains
npm
flowise-components, flowise
High
4 months ago
Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)
npm
flowise-components, flowise
High
4 months ago
Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
npm
flowise-components, flowise
High
4 months ago
Flowise: Parameter Override Bypass Remote Command Execution
npm
flowise-components, flowise
Critical
4 months ago
Flowise: Code Injection in CSVAgent leads to Authenticated RCE
npm
flowise-components, flowise
High
4 months ago
Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.
npm
flowise-components, flowise
Moderate
4 months ago
Flowise Execute Flow function has an SSRF vulnerability
npm
flowise-components, flowise
Moderate
4 months ago
Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)
npm
flowise-components, flowise
Moderate
4 months ago
Flowise: Path Traversal in Vector Store basePath
npm
flowise-components, flowise
High
10 months ago
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
npm
flowise-components, flowise
Critical
10 months ago
Flowise is vulnerable to arbitrary file write through its WriteFileTool
npm
flowise-components, flowise
High
over 1 year ago
Flowise Vulnerable to SQL Injection via `tableName` Parameter
npm
flowise-components