flowise-components vulnerabilities
CVEs whose affected-version data names the flowise-components package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
GHSA-88pr-878c-24wfHighFlowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
▾ Twilightflowise-components · flowise-componentsvia GHSA
CVE-2026-56275Medium· 7.1Flowise Execute Flow function has an SSRF vulnerability
Flowise Execute Flow function has an SSRF vulnerability
▾ Sunlitflowise · flowiseEPSS 0.32%via GHSA