Flowise is officially being sunset and will soon cease active maintenance or support. As a result, we are no longer accepting new security vulnerability reports for this repository. You can find more information here.
This repository was archived by the owner on Aug 13, 2026. It is now read-only.
Security: FlowiseAI/Flowise
Security
SECURITY.md
-
Broken access control in GET /api/v1/organizationuser leaks the organization owner's password hash to any member (privilege escalation/account takeover)GHSA-fhxm-xxcx-g6x3 published
Aug 28, 2026 by igor-magun-wdModerate -
Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via ChromiumGHSA-9gvv-qjj3-2p6g published
Jul 29, 2026 by igor-magun-wdCritical -
Authenticated Sandbox Escape and Data Exfiltration via Pandas Methods Bypass in pythonCodeValidatorGHSA-x58f-9m57-qc4m published
Jul 29, 2026 by igor-magun-wdHigh -
CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell VerifiedGHSA-vmv7-4m6c-3cg5 published
Jul 29, 2026 by igor-magun-wdCritical -
Evaluator create+update mass-assignment allows cross-workspace evaluator takeoverGHSA-wxrr-jp8m-qq7f published
May 14, 2026 by igor-magun-wdHigh -
Evaluation create+update mass-assignment allows cross-workspace evaluation takeoverGHSA-mq53-pc65-wjc4 published
May 14, 2026 by igor-magun-wdHigh -
Dataset create+update mass-assignment allows cross-workspace dataset takeoverGHSA-5h9v-837x-m97r published
May 14, 2026 by igor-magun-wdHigh -
DatasetRow create+update mass-assignment allows cross-workspace row takeoverGHSA-7j65-65cr-6644 published
May 14, 2026 by igor-magun-wdHigh -
CustomTemplate create+update mass-assignment allows cross-workspace template takeoverGHSA-728h-4mwj-f2p4 published
May 14, 2026 by igor-magun-wdHigh -
Assistant create+update mass-assignment allows cross-workspace assistant takeoverGHSA-78pr-c5x5-jggc published
May 14, 2026 by igor-magun-wdHigh
Learn more about advisories related to FlowiseAI/Flowise in the GitHub Advisory Database