Skip to content

Flowise

AI Agents & Assistants

A visual builder for creating and managing AI agents

TypeScript Latest [email protected] · 1mo ago Security brief →

Features

  • Visual workflow editor for designing AI agent flows
  • Docker‑Compose and standalone Docker image deployment options
  • Node.js backend with React frontend in a mono‑repo setup
  • Extensible component system for third‑party node integrations

Security Response History

1 CVE
CVE Severity Disclosed Patched (this tool) vs Ecosystem Median
CVE-2025-31125 KEV medium
CVSS 5.3
2025-03-31 2025-06-12 2mo / median 9mo

Recent releases

View all 14 releases →
[email protected] Security relevant
Security fixes
  • Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse
  • Credential data leak vulnerability
  • Multiple mass assignment vulnerabilities across Tools, Variables, Chatflow, Assistant, Dataset, and Custom Template endpoints
Notable features
  • Pipedream MCP integration
  • Browserless MCP integration
  • Email change confirmation flow
[email protected] Breaking risk
Breaking changes
  • HTTP security checks enabled by default — blocks localhost, 127.0.0.1, and internal addresses unless configured via HTTP_SECURITY_CHECK=false or HTTP_DENY_LIST
Security fixes
  • Default HTTP deny list for SSRF mitigation
  • Path traversal protections
  • HTTPS enforcement for user-provided URLs
Notable features
  • Azure Blob Storage support
  • AWS STS AssumeRole support
  • AgentFlow SDK (@flowiseai/agentflow v0.0.0-dev.2)
[email protected] Breaking risk
Security fixes
  • Mass assignment prevention in registration
  • DNS rebinding/TOCTOU vulnerability mitigation
Notable features
  • Azure Rerankers support
  • ChatCerebras v3.0 enhancement
  • Ollama Cloud integration

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
53,267
Forks
24,460
Languages
TypeScript JavaScript HTML
Downloads/week
23 ↓65%
NPM Maintainers
1
Contributors
332
TypeScript
Types included ✓

Install & Platforms

Install via
npm

Community & Support

Beta — feedback welcome: [email protected]