The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,270
Mitigations16,213
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
flowise<= 3.1.2
NPM: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
9.4
22 minutes ago
flowise-components<= 3.1.2
NPM: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
9.4
22 minutes ago
flowise<= 3.1.2
NPM: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
7.2
22 minutes ago
flowise-components<= 3.1.2
NPM: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
7.2
22 minutes ago
flowise<= 3.1.2
NPM: Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
7.1
22 minutes ago
flowise<= 3.1.2
NPM: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
9.5
35 minutes ago
flowise-components<= 3.1.2
NPM: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
9.5
35 minutes ago
flowise<= 3.1.2
NPM: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
8.7
56 minutes ago
flowise-components<= 3.1.2
NPM: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
8.7
56 minutes ago
flowise<= 3.1.2
NPM: Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
7.1
1 hour ago
flowise<= 3.1.2
NPM: Flowise RCE via SQLite Record Manager Node
9.4
2 hours ago
flowise-components<= 3.1.2
NPM: Flowise RCE via SQLite Record Manager Node
9.4
2 hours ago
flowise<= 3.1.2
NPM: Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
8.8
2 hours ago
flowise<= 3.1.2
NPM: Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
7.6
2 hours ago
flowise<= 3.1.2
NPM: Remote Code Execution Vulnerability in CSVAgent
9.4
2 hours ago
flowise-components<= 3.1.2
NPM: Remote Code Execution Vulnerability in CSVAgent
9.4
2 hours ago
flowise<= 3.1.2
NPM: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
9.2
2 hours ago
flowise-components<= 3.1.2
NPM: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
9.2
2 hours ago
flowise<= 3.1.2
NPM: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
9.4
2 hours ago
flowise-components<= 3.1.2
NPM: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
9.4
2 hours ago