{"data":{"ecosystem":"npm","name":"flowise-components","url":"https://aisecwatch.com/packages/npm/flowise-components","latestVersion":"3.1.4","firstReleaseAt":"2023-04-10T19:38:55.945Z","repository":null,"llm":{"exposure":"direct","depth":0,"integratedAt":"2023-04-10T19:38:55.945Z","integratedVersion":"1.0.0","sdks":["anthropic","bedrock","chromadb","cohere","google-genai","groq","huggingface","langchain","langgraph","llama-index","mcp","milvus","mistralai","ollama","openai","pinecone","qdrant","replicate","weaviate"],"path":[]},"authority":{"profile":["browser","execution","http","mcp_tools"],"fromDependencies":["npm:@e2b/code-interpreter","npm:@modelcontextprotocol/sdk","npm:@modelcontextprotocol/server-postgres","npm:@modelcontextprotocol/server-sequential-thinking","npm:@modelcontextprotocol/server-slack","npm:axios","npm:node-fetch","npm:playwright","npm:puppeteer","npm:vm2"]},"dependencies":[{"ecosystem":"npm","name":"@anthropic-ai/sdk","versionSpec":"^0.73.0","scope":"runtime"},{"ecosystem":"npm","name":"@aws-sdk/client-bedrock-runtime","versionSpec":"^3.1014.0","scope":"runtime"},{"ecosystem":"npm","name":"@brave/brave-search-mcp-server","versionSpec":"2.0.80","scope":"runtime"},{"ecosystem":"npm","name":"chromadb","versionSpec":"3.1.6","scope":"runtime"},{"ecosystem":"npm","name":"cohere-ai","versionSpec":"^7.7.5","scope":"runtime"},{"ecosystem":"npm","name":"exa-js","versionSpec":"^1.0.12","scope":"runtime"},{"ecosystem":"npm","name":"@google/generative-ai","versionSpec":"^0.24.0","scope":"runtime"},{"ecosystem":"npm","name":"groq-sdk","versionSpec":"1.1.2","scope":"runtime"},{"ecosystem":"npm","name":"@huggingface/inference","versionSpec":"^4.13.2","scope":"runtime"},{"ecosystem":"npm","name":"langchain","versionSpec":"1.2.18","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/anthropic","versionSpec":"1.3.20","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/aws","versionSpec":"1.2.2","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/baidu-qianfan","versionSpec":"1.0.1","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/classic","versionSpec":"1.0.15","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/cloudflare","versionSpec":"1.0.1","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/cohere","versionSpec":"1.0.2","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/community","versionSpec":"1.1.12","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/core","versionSpec":"1.1.20","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/deepseek","versionSpec":"1.0.9","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/exa","versionSpec":"1.0.1","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/google-genai","versionSpec":"2.1.15","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/google-vertexai","versionSpec":"2.1.15","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/groq","versionSpec":"1.0.4","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/langgraph","versionSpec":"^0.0.22","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/mistralai","versionSpec":"1.0.4","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/mongodb","versionSpec":"1.1.0","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/ollama","versionSpec":"1.2.2","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/openai","versionSpec":"1.2.5","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/pinecone","versionSpec":"1.0.1","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/qdrant","versionSpec":"1.0.1","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/redis","versionSpec":"1.1.0","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/tavily","versionSpec":"1.2.0","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/textsplitters","versionSpec":"1.0.1","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/weaviate","versionSpec":"1.0.1","scope":"runtime"},{"ecosystem":"npm","name":"@langchain/xai","versionSpec":"1.3.1","scope":"runtime"},{"ecosystem":"npm","name":"llamaindex","versionSpec":"^0.3.13","scope":"runtime"},{"ecosystem":"npm","name":"@mem0/community","versionSpec":"^0.0.1","scope":"runtime"},{"ecosystem":"npm","name":"@mistralai/mistralai","versionSpec":"1.14.0","scope":"runtime"},{"ecosystem":"npm","name":"@modelcontextprotocol/sdk","versionSpec":"1.29.0","scope":"runtime"},{"ecosystem":"npm","name":"@modelcontextprotocol/server-postgres","versionSpec":"^0.6.2","scope":"runtime"},{"ecosystem":"npm","name":"@modelcontextprotocol/server-sequential-thinking","versionSpec":"2025.12.18","scope":"runtime"},{"ecosystem":"npm","name":"@modelcontextprotocol/server-slack","versionSpec":"^2025.1.17","scope":"runtime"},{"ecosystem":"npm","name":"ollama","versionSpec":"^0.5.11","scope":"runtime"},{"ecosystem":"npm","name":"openai","versionSpec":"6.19.0","scope":"runtime"},{"ecosystem":"npm","name":"@pinecone-database/pinecone","versionSpec":"4.0.0","scope":"runtime"},{"ecosystem":"npm","name":"@qdrant/js-client-rest","versionSpec":"^1.18.0","scope":"runtime"},{"ecosystem":"npm","name":"replicate","versionSpec":"^0.31.1","scope":"runtime"},{"ecosystem":"npm","name":"@stripe/agent-toolkit","versionSpec":"^0.1.20","scope":"runtime"},{"ecosystem":"npm","name":"supergateway","versionSpec":"3.0.1","scope":"runtime"},{"ecosystem":"npm","name":"weaviate-client","versionSpec":"3.12.0","scope":"runtime"},{"ecosystem":"npm","name":"@zilliz/milvus2-sdk-node","versionSpec":"^2.2.24","scope":"runtime"},{"ecosystem":"npm","name":"@apidevtools/json-schema-ref-parser","versionSpec":"^11.7.0","scope":"runtime"},{"ecosystem":"npm","name":"apify-client","versionSpec":"^2.7.1","scope":"runtime"},{"ecosystem":"npm","name":"@arizeai/openinference-instrumentation-langchain","versionSpec":"^2.0.0","scope":"runtime"},{"ecosystem":"npm","name":"assemblyai","versionSpec":"^4.2.2","scope":"runtime"},{"ecosystem":"npm","name":"@aws-sdk/client-bedrock","versionSpec":"^3.1014.0","scope":"runtime"},{"ecosystem":"npm","name":"@aws-sdk/client-dynamodb","versionSpec":"^3.1014.0","scope":"runtime"},{"ecosystem":"npm","name":"@aws-sdk/client-kendra","versionSpec":"^3.1014.0","scope":"runtime"},{"ecosystem":"npm","name":"@aws-sdk/client-s3","versionSpec":"^3.1014.0","scope":"runtime"},{"ecosystem":"npm","name":"@aws-sdk/client-secrets-manager","versionSpec":"^3.1014.0","scope":"runtime"},{"ecosystem":"npm","name":"@aws-sdk/client-sns","versionSpec":"^3.1014.0","scope":"runtime"},{"ecosystem":"npm","name":"@aws-sdk/client-sts","versionSpec":"^3.1014.0","scope":"runtime"},{"ecosystem":"npm","name":"axios","versionSpec":"1.15.0","scope":"runtime"},{"ecosystem":"npm","name":"@azure/storage-blob","versionSpec":"^12.29.0","scope":"runtime"},{"ecosystem":"npm","name":"cheerio","versionSpec":"^1.0.0-rc.12","scope":"runtime"},{"ecosystem":"npm","name":"composio-core","versionSpec":"^0.5.39","scope":"runtime"},{"ecosystem":"npm","name":"couchbase","versionSpec":"4.4.1","scope":"runtime"},{"ecosystem":"npm","name":"crypto-js","versionSpec":"^4.1.1","scope":"runtime"},{"ecosystem":"npm","name":"css-what","versionSpec":"^6.1.0","scope":"runtime"},{"ecosystem":"npm","name":"d3-dsv","versionSpec":"2","scope":"runtime"},{"ecosystem":"npm","name":"@datastax/astra-db-ts","versionSpec":"1.5.0","scope":"runtime"},{"ecosystem":"npm","name":"dotenv","versionSpec":"^16.0.0","scope":"runtime"},{"ecosystem":"npm","name":"@dqbd/tiktoken","versionSpec":"^1.0.21","scope":"runtime"},{"ecosystem":"npm","name":"@e2b/code-interpreter","versionSpec":"^1.5.1","scope":"runtime"},{"ecosystem":"npm","name":"@elastic/elasticsearch","versionSpec":"^8.16.0","scope":"runtime"},{"ecosystem":"npm","name":"@elevenlabs/elevenlabs-js","versionSpec":"^2.8.0","scope":"runtime"},{"ecosystem":"npm","name":"epub2","versionSpec":"^3.0.2","scope":"runtime"},{"ecosystem":"npm","name":"express","versionSpec":"^4.17.3","scope":"runtime"},{"ecosystem":"npm","name":"faiss-node","versionSpec":"^0.5.1","scope":"runtime"},{"ecosystem":"npm","name":"fast-json-patch","versionSpec":"^3.1.1","scope":"runtime"},{"ecosystem":"npm","name":"form-data","versionSpec":"^4.0.4","scope":"runtime"},{"ecosystem":"npm","name":"@getzep/zep-cloud","versionSpec":"~1.0.7","scope":"runtime"},{"ecosystem":"npm","name":"@getzep/zep-js","versionSpec":"^0.9.0","scope":"runtime"},{"ecosystem":"npm","name":"@gomomento/sdk","versionSpec":"^1.51.1","scope":"runtime"},{"ecosystem":"npm","name":"@gomomento/sdk-core","versionSpec":"^1.51.1","scope":"runtime"},{"ecosystem":"npm","name":"@google-ai/generativelanguage","versionSpec":"^2.5.0","scope":"runtime"},{"ecosystem":"npm","name":"google-auth-library","versionSpec":"^9.4.0","scope":"runtime"},{"ecosystem":"npm","name":"@google-cloud/storage","versionSpec":"^7.15.2","scope":"runtime"},{"ecosystem":"npm","name":"graphql","versionSpec":"^16.6.0","scope":"runtime"},{"ecosystem":"npm","name":"@grpc/grpc-js","versionSpec":"^1.10.10","scope":"runtime"},{"ecosystem":"npm","name":"html-to-text","versionSpec":"^9.0.5","scope":"runtime"},{"ecosystem":"npm","name":"@ibm-cloud/watsonx-ai","versionSpec":"1.7.7","scope":"runtime"},{"ecosystem":"npm","name":"ioredis","versionSpec":"^5.3.2","scope":"runtime"},{"ecosystem":"npm","name":"ipaddr.js","versionSpec":"^2.2.0","scope":"runtime"},{"ecosystem":"npm","name":"jsdom","versionSpec":"^22.1.0","scope":"runtime"},{"ecosystem":"npm","name":"json5","versionSpec":"2.2.3","scope":"runtime"},{"ecosystem":"npm","name":"jsonpointer","versionSpec":"^5.0.1","scope":"runtime"},{"ecosystem":"npm","name":"jsonrepair","versionSpec":"^3.11.1","scope":"runtime"},{"ecosystem":"npm","name":"langfuse","versionSpec":"3.3.4","scope":"runtime"},{"ecosystem":"npm","name":"langfuse-langchain","versionSpec":"^3.3.4","scope":"runtime"},{"ecosystem":"npm","name":"langsmith","versionSpec":"0.4.12","scope":"runtime"},{"ecosystem":"npm","name":"langwatch","versionSpec":"^0.1.1","scope":"runtime"},{"ecosystem":"npm","name":"linkifyjs","versionSpec":"^4.3.2","scope":"runtime"},{"ecosystem":"npm","name":"lodash","versionSpec":"^4.17.21","scope":"runtime"},{"ecosystem":"npm","name":"lunary","versionSpec":"^0.7.12","scope":"runtime"},{"ecosystem":"npm","name":"mammoth","versionSpec":"^1.5.1","scope":"runtime"},{"ecosystem":"npm","name":"meilisearch","versionSpec":"^0.41.0","scope":"runtime"},{"ecosystem":"npm","name":"@mendable/firecrawl-js","versionSpec":"^1.18.2","scope":"runtime"},{"ecosystem":"npm","name":"moment","versionSpec":"^2.29.3","scope":"runtime"},{"ecosystem":"npm","name":"mongodb","versionSpec":"6.3.0","scope":"runtime"},{"ecosystem":"npm","name":"mysql2","versionSpec":"^3.11.3","scope":"runtime"},{"ecosystem":"npm","name":"neo4j-driver","versionSpec":"^5.26.0","scope":"runtime"},{"ecosystem":"npm","name":"node-fetch","versionSpec":"^2.6.11","scope":"runtime"},{"ecosystem":"npm","name":"node-html-markdown","versionSpec":"^1.3.0","scope":"runtime"},{"ecosystem":"npm","name":"@notionhq/client","versionSpec":"^2.2.8","scope":"runtime"},{"ecosystem":"npm","name":"notion-to-md","versionSpec":"^3.1.1","scope":"runtime"},{"ecosystem":"npm","name":"object-hash","versionSpec":"^3.0.0","scope":"runtime"},{"ecosystem":"npm","name":"officeparser","versionSpec":"5.1.1","scope":"runtime"},{"ecosystem":"npm","name":"@opensearch-project/opensearch","versionSpec":"^1.2.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/api","versionSpec":"1.9.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/auto-instrumentations-node","versionSpec":"^0.52.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/core","versionSpec":"1.27.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/exporter-metrics-otlp-grpc","versionSpec":"0.54.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/exporter-metrics-otlp-http","versionSpec":"0.54.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/exporter-metrics-otlp-proto","versionSpec":"0.54.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/exporter-trace-otlp-grpc","versionSpec":"0.54.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/exporter-trace-otlp-http","versionSpec":"0.54.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/exporter-trace-otlp-proto","versionSpec":"0.54.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/resources","versionSpec":"1.27.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/sdk-metrics","versionSpec":"1.27.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/sdk-node","versionSpec":"^0.54.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/sdk-trace-base","versionSpec":"1.27.0","scope":"runtime"},{"ecosystem":"npm","name":"@opentelemetry/semantic-conventions","versionSpec":"1.27.0","scope":"runtime"},{"ecosystem":"npm","name":"papaparse","versionSpec":"^5.4.1","scope":"runtime"},{"ecosystem":"npm","name":"pdfjs-dist","versionSpec":"^5.3.93","scope":"runtime"},{"ecosystem":"npm","name":"pdf-parse","versionSpec":"^1.1.1","scope":"runtime"},{"ecosystem":"npm","name":"pg","versionSpec":"^8.11.2","scope":"runtime"},{"ecosystem":"npm","name":"playwright","versionSpec":"^1.35.0","scope":"runtime"},{"ecosystem":"npm","name":"puppeteer","versionSpec":"^20.7.1","scope":"runtime"},{"ecosystem":"npm","name":"redis","versionSpec":"^4.6.7","scope":"runtime"},{"ecosystem":"npm","name":"remove-markdown","versionSpec":"^0.6.2","scope":"runtime"},{"ecosystem":"npm","name":"sanitize-filename","versionSpec":"^1.6.3","scope":"runtime"},{"ecosystem":"npm","name":"srt-parser-2","versionSpec":"^1.2.3","scope":"runtime"},{"ecosystem":"npm","name":"@supabase/supabase-js","versionSpec":"^2.29.0","scope":"runtime"},{"ecosystem":"npm","name":"typeorm","versionSpec":"^0.3.28","scope":"runtime"},{"ecosystem":"npm","name":"@types/jsdom","versionSpec":"^21.1.1","scope":"runtime"},{"ecosystem":"npm","name":"@types/js-yaml","versionSpec":"^4.0.5","scope":"runtime"},{"ecosystem":"npm","name":"@upstash/redis","versionSpec":"1.22.1","scope":"runtime"},{"ecosystem":"npm","name":"@upstash/vector","versionSpec":"1.1.5","scope":"runtime"},{"ecosystem":"npm","name":"uuid","versionSpec":"^10.0.0","scope":"runtime"},{"ecosystem":"npm","name":"vm2","versionSpec":"3.11.2","scope":"runtime"},{"ecosystem":"npm","name":"winston","versionSpec":"^3.9.0","scope":"runtime"},{"ecosystem":"npm","name":"ws","versionSpec":"^8.18.0","scope":"runtime"},{"ecosystem":"npm","name":"xlsx","versionSpec":"0.18.5","scope":"runtime"},{"ecosystem":"npm","name":"zod","versionSpec":"^3.25.76 || ^4","scope":"runtime"},{"ecosystem":"npm","name":"zod-to-json-schema","versionSpec":"^3.24.6","scope":"runtime"}],"advisories":[{"id":"5d60ea86-765c-4612-a285-f66230a9e617","url":"https://aisecwatch.com/issues/5d60ea86-765c-4612-a285-f66230a9e617","cveId":"CVE-2026-73483","title":"GHSA-9gvv-qjj3-2p6g: Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via Chromium","headline":null,"severity":"critical","publishedAt":"2026-10-07T16:17:02.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00621},{"id":"d6c8e7b4-8965-4a01-82a0-6964e4b27faf","url":"https://aisecwatch.com/issues/d6c8e7b4-8965-4a01-82a0-6964e4b27faf","cveId":"CVE-2026-73487","title":"CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows…","headline":"Flowise Python code validator bypass in CSV and Airtable Agent nodes","severity":"critical","publishedAt":"2026-08-13T12:17:24.083Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)","flowise-components@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00961},{"id":"0d4bb36c-7798-4fc7-b3a1-343515949157","url":"https://aisecwatch.com/issues/0d4bb36c-7798-4fc7-b3a1-343515949157","cveId":"CVE-2026-70477","title":"GHSA-5xvg-pmgg-3mxr: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability","headline":null,"severity":"critical","publishedAt":"2026-08-04T19:29:26.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00814},{"id":"ed4819d5-4302-4207-bf57-ea2e3b9707ce","url":"https://aisecwatch.com/issues/ed4819d5-4302-4207-bf57-ea2e3b9707ce","cveId":"CVE-2026-69264","title":"GHSA-4j8x-x6v7-w9rq: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation","headline":null,"severity":"critical","publishedAt":"2026-08-04T17:43:48.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.01112},{"id":"c89f11a7-a283-4635-a897-4dbfc69ff1c9","url":"https://aisecwatch.com/issues/c89f11a7-a283-4635-a897-4dbfc69ff1c9","cveId":null,"title":"GHSA-88pr-878c-24wf: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys                                                                                                  ","headline":null,"severity":"high","publishedAt":"2026-08-04T17:43:45.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)","flowise-components@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":null},{"id":"89215702-e795-41b5-b522-ae8937becf80","url":"https://aisecwatch.com/issues/89215702-e795-41b5-b522-ae8937becf80","cveId":"CVE-2026-70470","title":"GHSA-52fh-8v99-63c2: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE","headline":null,"severity":"critical","publishedAt":"2026-08-04T17:31:09.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00972},{"id":"a364d053-ab58-4a76-9620-5912d582b021","url":"https://aisecwatch.com/issues/a364d053-ab58-4a76-9620-5912d582b021","cveId":"CVE-2026-69263","title":"GHSA-xc48-889x-5qmw: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)","headline":null,"severity":"high","publishedAt":"2026-08-04T17:09:48.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00662},{"id":"ca5dbda8-1b8c-46fc-b04b-5c3d7a0758fa","url":"https://aisecwatch.com/issues/ca5dbda8-1b8c-46fc-b04b-5c3d7a0758fa","cveId":"CVE-2026-69259","title":"GHSA-x3hf-7cj6-3r4m: Flowise RCE via SQLite Record Manager Node","headline":null,"severity":"critical","publishedAt":"2026-08-04T16:05:10.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00821},{"id":"413cb1e4-00ef-482e-a271-6f5afeecdfc6","url":"https://aisecwatch.com/issues/413cb1e4-00ef-482e-a271-6f5afeecdfc6","cveId":"CVE-2026-69256","title":"GHSA-x6vm-w76m-8j7g: Flowise: Remote Code Execution Vulnerability in CSVAgent","headline":null,"severity":"critical","publishedAt":"2026-08-04T15:46:20.000Z","affected":["flowise@<= 3.1.2 (fixed: 3.1.3)","flowise-components@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.0101},{"id":"5386ddd7-42db-4579-95af-dfee9174671d","url":"https://aisecwatch.com/issues/5386ddd7-42db-4579-95af-dfee9174671d","cveId":"CVE-2026-69255","title":"GHSA-vmv7-4m6c-3cg5: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified","headline":null,"severity":"critical","publishedAt":"2026-08-04T15:40:28.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00716},{"id":"7ba8c4df-3b36-4f94-b37d-b1d5ddc2c30c","url":"https://aisecwatch.com/issues/7ba8c4df-3b36-4f94-b37d-b1d5ddc2c30c","cveId":"CVE-2026-69254","title":"GHSA-3769-jgqc-cxm7: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override","headline":null,"severity":"critical","publishedAt":"2026-08-04T15:29:12.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00691},{"id":"f56747d0-7df8-4ff8-ba83-0d98d5fd9949","url":"https://aisecwatch.com/issues/f56747d0-7df8-4ff8-ba83-0d98d5fd9949","cveId":"CVE-2026-69253","title":"GHSA-wg86-r78f-74mp: Flowise Sandbox Escape to RCE","headline":null,"severity":"critical","publishedAt":"2026-08-04T15:13:33.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.00664},{"id":"6b03abdb-eb72-46c2-a9a6-779620d705b1","url":"https://aisecwatch.com/issues/6b03abdb-eb72-46c2-a9a6-779620d705b1","cveId":"CVE-2026-69251","title":"GHSA-g32j-mmxr-gfq5: Flowise RCE via TypeORM DataSource","headline":null,"severity":"critical","publishedAt":"2026-08-04T14:28:04.000Z","affected":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"epssScore":0.02742},{"id":"185696db-2282-4cc5-baf2-7e55eb9d51be","url":"https://aisecwatch.com/issues/185696db-2282-4cc5-baf2-7e55eb9d51be","cveId":null,"title":"GHSA-m99r-2hxc-cp3q: Flowise has an MCP Security Bypass that Enables RCE","headline":null,"severity":"high","publishedAt":"2026-05-14T14:57:30.000Z","affected":["flowise-components@<= 3.1.1 (fixed: 3.1.2)","flowise@<= 3.1.1 (fixed: 3.1.2)"],"epssScore":null},{"id":"4e0bd950-f01e-4da1-8032-a2df8c7678c7","url":"https://aisecwatch.com/issues/4e0bd950-f01e-4da1-8032-a2df8c7678c7","cveId":"CVE-2026-43995","title":"CVE-2026-43995: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool…","headline":"Flowise tools bypass secured wrapper and invoke raw HTTP clients","severity":"medium","publishedAt":"2026-05-11T18:16:37.660Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00484},{"id":"db5616eb-c907-46b3-93fe-9f055704457e","url":"https://aisecwatch.com/issues/db5616eb-c907-46b3-93fe-9f055704457e","cveId":"CVE-2026-41274","title":"CVE-2026-41274: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the…","headline":"Flowise GraphCypherQAChain node Cypher injection into Neo4j database","severity":"critical","publishedAt":"2026-04-23T22:16:38.740Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00735},{"id":"bd022616-d025-431d-9cd3-b398718546a9","url":"https://aisecwatch.com/issues/bd022616-d025-431d-9cd3-b398718546a9","cveId":"CVE-2026-41272","title":"CVE-2026-41272: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core…","headline":"Flowise SSRF protection bypass via DNS rebinding and default configuration","severity":"high","publishedAt":"2026-04-23T20:16:15.810Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00354},{"id":"9e77eaca-1304-493f-ba38-cedd8b70aec7","url":"https://aisecwatch.com/issues/9e77eaca-1304-493f-ba38-cedd8b70aec7","cveId":"CVE-2026-41271","title":"CVE-2026-41271: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side…","headline":"Flowise server-side request forgery in POST/GET API Chain components","severity":"high","publishedAt":"2026-04-23T20:16:15.683Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00342},{"id":"3f5b8e7a-9823-44c0-960d-71bf00127372","url":"https://aisecwatch.com/issues/3f5b8e7a-9823-44c0-960d-71bf00127372","cveId":"CVE-2026-41270","title":"CVE-2026-41270: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side…","headline":"Flowise SSRF protection bypass in Custom Function feature","severity":"high","publishedAt":"2026-04-23T20:16:15.547Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00332},{"id":"9e1452d8-5767-420e-a4ba-bb2e23b01072","url":"https://aisecwatch.com/issues/9e1452d8-5767-420e-a4ba-bb2e23b01072","cveId":"CVE-2026-41268","title":"CVE-2026-41268: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is…","headline":"Flowise unauthenticated remote command execution via parameter override bypass","severity":"critical","publishedAt":"2026-04-23T20:16:15.300Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.01247},{"id":"d9688a7f-f181-43d3-a9d8-4aa865d516bf","url":"https://aisecwatch.com/issues/d9688a7f-f181-43d3-a9d8-4aa865d516bf","cveId":"CVE-2026-41265","title":"CVE-2026-41265: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific…","headline":"Flowise command execution via prompt injection in Airtable Agent node","severity":"critical","publishedAt":"2026-04-23T20:16:14.890Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00555},{"id":"fa4bef48-e49c-43f4-888c-2527a9bff35a","url":"https://aisecwatch.com/issues/fa4bef48-e49c-43f4-888c-2527a9bff35a","cveId":"CVE-2026-41138","title":"CVE-2026-41138: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a…","headline":"Flowise remote code execution through AirtableAgent Pandas prompt input","severity":"critical","publishedAt":"2026-04-23T20:16:14.380Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.00845},{"id":"1641cc73-d00b-40ea-8d12-90ddd00d4339","url":"https://aisecwatch.com/issues/1641cc73-d00b-40ea-8d12-90ddd00d4339","cveId":"CVE-2026-41137","title":"CVE-2026-41137: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent…","headline":"Flowise command injection through CSVAgent custom Pandas CSV read code","severity":"critical","publishedAt":"2026-04-23T20:16:14.257Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.02051},{"id":"e2f0ed54-f2bf-4959-bc2b-50193b6e54ce","url":"https://aisecwatch.com/issues/e2f0ed54-f2bf-4959-bc2b-50193b6e54ce","cveId":"CVE-2026-40933","title":"CVE-2026-40933: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe…","headline":"Flowise command execution through Custom MCP stdio server configuration","severity":"critical","publishedAt":"2026-04-21T22:16:19.383Z","affected":["flowise@<= 3.0.13 (fixed: 3.1.0)","flowise-components@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.01283},{"id":"68e23887-4c48-4a58-acfb-59322d06e9c2","url":"https://aisecwatch.com/issues/68e23887-4c48-4a58-acfb-59322d06e9c2","cveId":"CVE-2026-41264","title":"GHSA-3hjv-c53m-58jj: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability","headline":null,"severity":"critical","publishedAt":"2026-04-21T20:19:52.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":0.01165},{"id":"507e419d-a9f0-488b-8218-047e9fc1f88f","url":"https://aisecwatch.com/issues/507e419d-a9f0-488b-8218-047e9fc1f88f","cveId":null,"title":"GHSA-v38x-c887-992f: Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability","headline":null,"severity":"critical","publishedAt":"2026-04-18T00:46:04.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null},{"id":"437a194c-be91-49be-a2cf-1e36f2e8286b","url":"https://aisecwatch.com/issues/437a194c-be91-49be-a2cf-1e36f2e8286b","cveId":null,"title":"GHSA-28g4-38q8-3cwc: Flowise: Cypher Injection in GraphCypherQAChain","headline":null,"severity":"high","publishedAt":"2026-04-16T21:54:26.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null},{"id":"3661703c-5c7c-4dc2-bddd-b9116db46ff4","url":"https://aisecwatch.com/issues/3661703c-5c7c-4dc2-bddd-b9116db46ff4","cveId":null,"title":"GHSA-6r77-hqx7-7vw8: Flowise:  APIChain Prompt Injection SSRF in GET/POST API Chains","headline":null,"severity":"high","publishedAt":"2026-04-16T21:52:11.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null},{"id":"1c85c082-06d4-4aa2-a39c-f1f0e10425a6","url":"https://aisecwatch.com/issues/1c85c082-06d4-4aa2-a39c-f1f0e10425a6","cveId":null,"title":"GHSA-2x8m-83vc-6wv4: Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)","headline":null,"severity":"high","publishedAt":"2026-04-16T21:51:00.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null},{"id":"7e7b6962-c0dc-4015-b091-42c85f2c6c50","url":"https://aisecwatch.com/issues/7e7b6962-c0dc-4015-b091-42c85f2c6c50","cveId":null,"title":"GHSA-xhmj-rg95-44hv: Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox","headline":null,"severity":"high","publishedAt":"2026-04-16T21:50:12.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null},{"id":"998fddfa-3b4a-439e-9f4a-2ec3e703417b","url":"https://aisecwatch.com/issues/998fddfa-3b4a-439e-9f4a-2ec3e703417b","cveId":null,"title":"GHSA-cvrr-qhgw-2mm6: Flowise: Parameter Override Bypass Remote Command Execution","headline":null,"severity":"high","publishedAt":"2026-04-16T21:46:39.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null},{"id":"58bd513d-fa76-4a5d-bbb0-c948e6a1cf14","url":"https://aisecwatch.com/issues/58bd513d-fa76-4a5d-bbb0-c948e6a1cf14","cveId":null,"title":"GHSA-9wc7-mj3f-74xv: Flowise: Code Injection in CSVAgent leads to Authenticated RCE","headline":null,"severity":"critical","publishedAt":"2026-04-16T21:44:15.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null},{"id":"7f2cdab6-751d-4130-a1f3-1e7e6a94dcf4","url":"https://aisecwatch.com/issues/7f2cdab6-751d-4130-a1f3-1e7e6a94dcf4","cveId":null,"title":"GHSA-f228-chmx-v6j6: Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.","headline":null,"severity":"high","publishedAt":"2026-04-16T21:43:57.000Z","affected":["flowise-components@<= 3.0.13 (fixed: 3.1.0)","flowise@<= 3.0.13 (fixed: 3.1.0)"],"epssScore":null},{"id":"8d91908b-5f36-4e29-8d09-121cedada4f8","url":"https://aisecwatch.com/issues/8d91908b-5f36-4e29-8d09-121cedada4f8","cveId":"CVE-2026-31829","title":"CVE-2026-31829: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise…","headline":"Flowise SSRF through HTTP Node in AgentFlow and Chatflow","severity":"high","publishedAt":"2026-03-10T22:16:20.937Z","affected":["flowise@<= 3.0.12 (fixed: 3.0.13)","flowise-components@<= 3.0.12 (fixed: 3.0.13)"],"epssScore":0.00391},{"id":"87941bf1-fa10-4cb3-a79b-8e5ad81ee7b0","url":"https://aisecwatch.com/issues/87941bf1-fa10-4cb3-a79b-8e5ad81ee7b0","cveId":"CVE-2025-61913","title":"CVE-2025-61913: Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8…","headline":"Flowise path traversal in WriteFileTool and ReadFileTool allows","severity":"critical","publishedAt":"2025-10-08T23:15:31.357Z","affected":["flowise@< 3.0.8 (fixed: 3.0.8)","flowise-components@< 3.0.8 (fixed: 3.0.8)","Flowise@<= 3.0.5 (fixed: 3.0.8)"],"epssScore":0.1295}],"checkedAt":"2026-10-09T22:31:03.683Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}