npm

flowise-components

View on npm registry
29 Total advisories
29 Vulnerabilities
0 Malware

Dependency scanning

Check whether flowise-components is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
npm

CVE-2026-70477

Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

UNKNOWN
npm

CVE-2026-69256

Flowise: Remote Code Execution Vulnerability in CSVAgent

UNKNOWN
npm

GHSA-88pr-878c-24wf

Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys

UNKNOWN
npm

CVE-2026-69264

Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation

UNKNOWN
npm

CVE-2026-70470

Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE

UNKNOWN
npm

CVE-2026-69263

Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)

UNKNOWN
npm

CVE-2026-69259

Flowise RCE via SQLite Record Manager Node

UNKNOWN
npm

CVE-2026-69254

Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override

UNKNOWN
npm

CVE-2026-69255

Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified

UNKNOWN
npm

CVE-2026-69253

Flowise Sandbox Escape to RCE

UNKNOWN
npm

CVE-2026-69251

Flowise RCE via TypeORM DataSource

UNKNOWN
npm

CVE-2026-56273

Flowise: Path Traversal in Vector Store basePath

UNKNOWN
npm

CVE-2026-56274

Flowise has an MCP Security Bypass that Enables RCE

UNKNOWN
npm

CVE-2026-56275

Flowise Execute Flow function has an SSRF vulnerability

UNKNOWN
npm

CVE-2026-43995

Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)

HIGH 7.1
npm

CVE-2026-41270

Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox

CRITICAL 9.8
npm

CVE-2026-41265

Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability

HIGH 8.3
npm

CVE-2026-41138

Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.

HIGH 7.7
npm

CVE-2026-41268

Flowise: Parameter Override Bypass Remote Command Execution

HIGH 8.8
npm

CVE-2026-41137

Flowise: Code Injection in CSVAgent leads to Authenticated RCE

HIGH 7.1
npm

CVE-2026-41271

Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains

CRITICAL 9.8
npm

CVE-2026-41264

Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

HIGH 7.1
npm

CVE-2026-41272

Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)

UNKNOWN
npm

CVE-2026-41274

Flowise: Cypher Injection in GraphCypherQAChain

CRITICAL 9.9
npm

CVE-2026-40933

Flowise: Authenticated RCE Via MCP Adapters

HIGH 7.1
npm

CVE-2026-31829

Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access

CRITICAL 9.9
npm

CVE-2025-61913

Flowise is vulnerable to arbitrary file write through its WriteFileTool

HIGH 7.7
npm

GHSA-j44m-5v8f-gc9c

Flowise is vulnerable to arbitrary file exposure through its ReadFileTool

HIGH 7.6
npm

CVE-2025-29189

Flowise Vulnerable to SQL Injection via `tableName` Parameter

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes