Flowise is officially being sunset and will soon cease active maintenance or support. As a result, we are no longer accepting new security vulnerability reports for this repository. You can find more information here.
This repository was archived by the owner on Aug 13, 2026. It is now read-only.
Security: FlowiseAI/Flowise
Security
SECURITY.md
-
RCE in FlowiseAI/FlowiseGHSA-3gcm-f6qx-ff7p published
Sep 13, 2025 by HenryHengZJCritical -
File Upload in FlowiseAI/FlowiseGHSA-35g6-rrw3-v6xc published
Oct 6, 2025 by HenryHengZJHigh -
Arbitrary File ReadGHSA-99pg-hqvx-r4gf published
Sep 13, 2025 by HenryHengZJCritical -
Critical Multi-Tenant Variable Disclosure in Flowise Cloud via Custom JavaScript FunctionGHSA-435c-mg9p-fv22 published
Sep 12, 2025 by HenryHengZJCritical -
FlowiseAI Pre-Auth Arbitrary Code ExecutionGHSA-7944-7c6r-55vv published
Sep 13, 2025 by HenryHengZJCritical -
XSS vulnerability in FlowiseGHSA-4fr9-3x69-36wv published
Oct 3, 2025 by HenryHengZJCritical -
Authentication Bypass Using Unprotected Registration Endpoint (/register)GHSA-v5w9-prxf-w882 published
Nov 15, 2025 by HenryHengZJCritical -
Authenticated Remote code execution (RCE) via Arbitrary File WriteGHSA-pr8x-mr56-fx5p published
Oct 8, 2025 by HenryHengZJCritical -
Flowise Authenticated Command Execution and Sandbox Bypass via Puppeteer and Playwright PackagesGHSA-5w3r-f6gm-c25w published
Oct 3, 2025 by HenryHengZJHigh -
Arbitrary file access due to missing chat flow id validationGHSA-q67q-549q-p849 published
Sep 13, 2025 by HenryHengZJCritical
Learn more about advisories related to FlowiseAI/Flowise in the GitHub Advisory Database