Dependency scanning
Check whether flowise-components is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-70477
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
CVE-2026-69256
Flowise: Remote Code Execution Vulnerability in CSVAgent
GHSA-88pr-878c-24wf
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
CVE-2026-69264
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
CVE-2026-70470
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
CVE-2026-69263
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
CVE-2026-69259
Flowise RCE via SQLite Record Manager Node
CVE-2026-69254
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
CVE-2026-69255
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
CVE-2026-69253
Flowise Sandbox Escape to RCE
CVE-2026-69251
Flowise RCE via TypeORM DataSource
CVE-2026-56273
Flowise: Path Traversal in Vector Store basePath
CVE-2026-56274
Flowise has an MCP Security Bypass that Enables RCE
CVE-2026-56275
Flowise Execute Flow function has an SSRF vulnerability
CVE-2026-43995
Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)
CVE-2026-41270
Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
CVE-2026-41265
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
CVE-2026-41138
Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.
CVE-2026-41268
Flowise: Parameter Override Bypass Remote Command Execution
CVE-2026-41137
Flowise: Code Injection in CSVAgent leads to Authenticated RCE
CVE-2026-41271
Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains
CVE-2026-41264
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
CVE-2026-41272
Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)
CVE-2026-41274
Flowise: Cypher Injection in GraphCypherQAChain
CVE-2026-40933
Flowise: Authenticated RCE Via MCP Adapters
CVE-2026-31829
Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access
CVE-2025-61913
Flowise is vulnerable to arbitrary file write through its WriteFileTool
GHSA-j44m-5v8f-gc9c
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
CVE-2025-29189
Flowise Vulnerable to SQL Injection via `tableName` Parameter
Browse more npm advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes