Skip to content

flowise-components

Flowiseai Components

Declares an LLM dependency since 2023-04-10 (version 1.0.0).

npmLatest 3.1.4First release 2023-04-10Registry pageChecked 2026-10-09

Advisories

Advisories that name flowise-components as affected. Advisory records do not state an ecosystem, so packages with the same name in other ecosystems also match. For a version-exact check of your own dependencies, use Stack Check.

AdvisorySeverityAffectedFixed inPublished
CVE-2026-73483GHSA-9gvv-qjj3-2p6g: Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via ChromiumCritical<= 3.1.23.1.32026-10-07
CVE-2026-73487CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows…Critical<= 3.1.23.1.32026-08-13
CVE-2026-70477GHSA-5xvg-pmgg-3mxr: Flowise: CSV Agent Prompt Injection Remote Code Execution VulnerabilityCritical<= 3.1.23.1.32026-08-04
CVE-2026-69264GHSA-4j8x-x6v7-w9rq: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validationCritical<= 3.1.23.1.32026-08-04
GHSA-88pr-878c-24wf: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys High<= 3.1.23.1.32026-08-04
CVE-2026-70470GHSA-52fh-8v99-63c2: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCECritical<= 3.1.23.1.32026-08-04
CVE-2026-69263GHSA-xc48-889x-5qmw: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)High<= 3.1.23.1.32026-08-04
CVE-2026-69259GHSA-x3hf-7cj6-3r4m: Flowise RCE via SQLite Record Manager NodeCritical<= 3.1.23.1.32026-08-04
CVE-2026-69256GHSA-x6vm-w76m-8j7g: Flowise: Remote Code Execution Vulnerability in CSVAgentCritical<= 3.1.23.1.32026-08-04
CVE-2026-69255GHSA-vmv7-4m6c-3cg5: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell VerifiedCritical<= 3.1.23.1.32026-08-04
CVE-2026-69254GHSA-3769-jgqc-cxm7: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions OverrideCritical<= 3.1.23.1.32026-08-04
CVE-2026-69253GHSA-wg86-r78f-74mp: Flowise Sandbox Escape to RCECritical<= 3.1.23.1.32026-08-04
CVE-2026-69251GHSA-g32j-mmxr-gfq5: Flowise RCE via TypeORM DataSourceCritical<= 3.1.23.1.32026-08-04
GHSA-m99r-2hxc-cp3q: Flowise has an MCP Security Bypass that Enables RCEHigh<= 3.1.13.1.22026-05-14
CVE-2026-43995CVE-2026-43995: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool…Medium<= 3.0.133.1.02026-05-11
CVE-2026-41274CVE-2026-41274: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the…Critical<= 3.0.133.1.02026-04-23
CVE-2026-41272CVE-2026-41272: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core…High<= 3.0.133.1.02026-04-23
CVE-2026-41271CVE-2026-41271: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side…High<= 3.0.133.1.02026-04-23
CVE-2026-41270CVE-2026-41270: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side…High<= 3.0.133.1.02026-04-23
CVE-2026-41268CVE-2026-41268: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is…Critical<= 3.0.133.1.02026-04-23
CVE-2026-41265CVE-2026-41265: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific…Critical<= 3.0.133.1.02026-04-23
CVE-2026-41138CVE-2026-41138: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a…Critical<= 3.0.133.1.02026-04-23
CVE-2026-41137CVE-2026-41137: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent…Critical<= 3.0.133.1.02026-04-23
CVE-2026-40933CVE-2026-40933: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe…Critical<= 3.0.133.1.02026-04-21
CVE-2026-41264GHSA-3hjv-c53m-58jj: Flowise: CSV Agent Prompt Injection Remote Code Execution VulnerabilityCritical<= 3.0.133.1.02026-04-21
GHSA-v38x-c887-992f: Flowise: Airtable_Agent Code Injection Remote Code Execution VulnerabilityCritical<= 3.0.133.1.02026-04-18
GHSA-28g4-38q8-3cwc: Flowise: Cypher Injection in GraphCypherQAChainHigh<= 3.0.133.1.02026-04-16
GHSA-6r77-hqx7-7vw8: Flowise: APIChain Prompt Injection SSRF in GET/POST API ChainsHigh<= 3.0.133.1.02026-04-16
GHSA-2x8m-83vc-6wv4: Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)High<= 3.0.133.1.02026-04-16
GHSA-xhmj-rg95-44hv: Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function SandboxHigh<= 3.0.133.1.02026-04-16
GHSA-cvrr-qhgw-2mm6: Flowise: Parameter Override Bypass Remote Command ExecutionHigh<= 3.0.133.1.02026-04-16
GHSA-9wc7-mj3f-74xv: Flowise: Code Injection in CSVAgent leads to Authenticated RCECritical<= 3.0.133.1.02026-04-16
GHSA-f228-chmx-v6j6: Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.High<= 3.0.133.1.02026-04-16
CVE-2026-31829CVE-2026-31829: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise…High<= 3.0.123.0.132026-03-10
CVE-2025-61913CVE-2025-61913: Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8…Critical< 3.0.83.0.82025-10-08

Dependencies of the latest release

As declared in npm metadata for version 3.1.4. Optional extras are listed with their extra name.

Tracked packages that depend on it

Among the packages in the registry; not every dependent on npm.