flowise-components vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-70477Criticalflowise: Flowise: CSV Agent Prompt Injection Remote Code Execution VulnerabilityCVE-2026-69264Criticalflowise: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validationGHSA-88PR-878C-24WFHighflowise-components: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys …CVE-2026-70470Criticalflowise: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCECVE-2026-69263Highflowise: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)CVE-2026-69259Criticalflowise: Flowise RCE via SQLite Record Manager NodeCVE-2026-69256Criticalflowise-components: Flowise: Remote Code Execution Vulnerability in CSVAgentCVE-2026-69255Criticalflowise: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell VerifiedCVE-2026-69254Criticalflowise: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions OverrideCVE-2026-69253Criticalflowise: Flowise Sandbox Escape to RCECVE-2026-69251Criticalflowise: Flowise RCE via TypeORM DataSourceGHSA-M99R-2HXC-CP3QHighflowise: Flowise has an MCP Security Bypass that Enables RCECVE-2026-41264Criticalflowise: Flowise: CSV Agent Prompt Injection Remote Code Execution VulnerabilityCVE-2026-41265Criticalflowise: Flowise: Airtable_Agent Code Injection Remote Code Execution VulnerabilityCVE-2026-41274Highflowise: Flowise: Cypher Injection in GraphCypherQAChainCVE-2026-41271Highflowise: Flowise: APIChain Prompt Injection SSRF in GET/POST API ChainsCVE-2026-41272Highflowise: Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)CVE-2026-41270Highflowise: Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function SandboxCVE-2026-41268Highflowise: Flowise: Parameter Override Bypass Remote Command ExecutionCVE-2026-41137Criticalflowise: Flowise: Code Injection in CSVAgent leads to Authenticated RCECVE-2026-41138Highflowise: Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.GHSA-9HRV-GVRV-6GF2Mediumflowise: Flowise Execute Flow function has an SSRF vulnerabilityCVE-2026-43995Mediumflowise: Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)GHSA-W6V6-49GH-MC9WMediumflowise: Flowise: Path Traversal in Vector Store basePathCVE-2026-40933Criticalflowise: Flowise: Authenticated RCE Via MCP Adapters

Stop the waste.
Protect your environment with Kodem.