This repository was archived by the owner on Aug 13, 2026. It is now read-only.
Security: FlowiseAI/Flowise
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Broken access control in GET /api/v1/organizationuser leaks the organization owner's password hash to any member (privilege escalation/account takeover)GHSA-fhxm-xxcx-g6x3 published
Aug 28, 2026 by igor-magun-wdModerate -
Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via ChromiumGHSA-9gvv-qjj3-2p6g published
Jul 29, 2026 by igor-magun-wdCritical -
Authenticated Sandbox Escape and Data Exfiltration via Pandas Methods Bypass in pythonCodeValidatorGHSA-x58f-9m57-qc4m published
Jul 29, 2026 by igor-magun-wdHigh -
CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell VerifiedGHSA-vmv7-4m6c-3cg5 published
Jul 29, 2026 by igor-magun-wdCritical -
Evaluator create+update mass-assignment allows cross-workspace evaluator takeoverGHSA-wxrr-jp8m-qq7f published
May 14, 2026 by igor-magun-wdHigh -
Evaluation create+update mass-assignment allows cross-workspace evaluation takeoverGHSA-mq53-pc65-wjc4 published
May 14, 2026 by igor-magun-wdHigh -
Dataset create+update mass-assignment allows cross-workspace dataset takeoverGHSA-5h9v-837x-m97r published
May 14, 2026 by igor-magun-wdHigh -
DatasetRow create+update mass-assignment allows cross-workspace row takeoverGHSA-7j65-65cr-6644 published
May 14, 2026 by igor-magun-wdHigh -
CustomTemplate create+update mass-assignment allows cross-workspace template takeoverGHSA-728h-4mwj-f2p4 published
May 14, 2026 by igor-magun-wdHigh -
Assistant create+update mass-assignment allows cross-workspace assistant takeoverGHSA-78pr-c5x5-jggc published
May 14, 2026 by igor-magun-wdHigh