OsVault/npm/flowise-components
npm

flowise-components

17 known vulnerabilities · 0 critical · 0 high

GHSA-28g4-38q8-3cwc

Flowise: Cypher Injection in GraphCypherQAChain

Published Apr 16, 2026
GHSA-6r77-hqx7-7vw8

Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains

Published Apr 16, 2026
GHSA-9hrv-gvrv-6gf2

Flowise Execute Flow function has an SSRF vulnerability

Published Apr 16, 2026
GHSA-qqvm-66q4-vf5c

Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)

Published Apr 16, 2026
GHSA-c9gw-hvqq-f33r

Flowise: Authenticated RCE Via MCP Adapters

Published Apr 16, 2026
GHSA-w6v6-49gh-mc9w

Flowise: Path Traversal in Vector Store basePath

Published Apr 16, 2026
GHSA-xhmj-rg95-44hv

Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox

Published Apr 16, 2026
GHSA-v38x-c887-992f

Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability

Published Apr 18, 2026
GHSA-3hjv-c53m-58jj

Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

Published Apr 21, 2026
GHSA-f228-chmx-v6j6

Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.

Published Apr 16, 2026
GHSA-9wc7-mj3f-74xv

Flowise: Code Injection in CSVAgent leads to Authenticated RCE

Published Apr 16, 2026
GHSA-cvrr-qhgw-2mm6

Flowise: Parameter Override Bypass Remote Command Execution

Published Apr 16, 2026
GHSA-j44m-5v8f-gc9c

Flowise is vulnerable to arbitrary file exposure through its ReadFileTool

Published Oct 10, 2025
GHSA-2x8m-83vc-6wv4

Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)

Published Apr 16, 2026
CVE-2025-61913

Flowise is vulnerable to arbitrary file write through its WriteFileTool

Published Oct 9, 2025
CVE-2026-31829

Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access

Published Mar 11, 2026
CVE-2025-29189

Flowise Vulnerable to SQL Injection via `tableName` Parameter

Published Apr 9, 2025
Check your entire dependency tree at onceRun dependency scan →