Flowise is officially being sunset and will soon cease active maintenance or support. As a result, we are no longer accepting new security vulnerability reports for this repository. You can find more information here.
Security: FlowiseAI/Flowise
Security
SECURITY.md
-
Mass Assignment in PUT /api/v1/user Allows Authenticated Users to Override Password Hash and Bypass Password Change VerificationGHSA-59fh-9f3p-7m39 published
May 14, 2026 by igor-magun-wdModerate -
Mass Assignment in Variable Update Endpoint Allows Cross-Workspace Resource ReassignmentGHSA-6fw7-3q8r-m5vj published
May 14, 2026 by igor-magun-wdHigh -
Mass Assignment in Assistant Update Endpoint Allows Cross-Workspace Resource ReassignmentGHSA-hp26-q66v-q2w7 published
May 14, 2026 by igor-magun-wdHigh -
Mass Assignment in Tool Update Endpoint Allows Cross-Workspace Resource ReassignmentGHSA-x5v6-pj28-cwwm published
May 14, 2026 by igor-magun-wdHigh -
Mass Assignment in Chatflow Update Endpoint Allows Cross-Workspace AgentFlow ReassignmentGHSA-5wxp-qjgq-fx6m published
May 14, 2026 by igor-magun-wdHigh -
RBAC Bypass Leading to Unauthorized Workspace Variables DisclosureGHSA-8r8h-6vcc-xhrv published
Jul 29, 2026 by igor-magun-wdHigh -
Flowise Execute Flow function has an SSRF vulnerabilityGHSA-9hrv-gvrv-6gf2 published
Apr 15, 2026 by igor-magun-wdModerate -
Flowise MCP Security Bypass Enables RCEGHSA-m99r-2hxc-cp3q published
May 14, 2026 by igor-magun-wdHigh -
Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpageGHSA-m837-xvxr-vqwg published
May 14, 2026 by igor-magun-wdModerate -
Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentialsGHSA-5fw2-mwhh-9947 published
Apr 15, 2026 by igor-magun-wdHigh
Learn more about advisories related to FlowiseAI/Flowise in the GitHub Advisory Database