Skip to content

Release history

Flowise releases

Build AI Agents, Visually

All releases

14 shown

[email protected] Security relevant
Security fixes
  • Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse
  • Credential data leak vulnerability
  • Multiple mass assignment vulnerabilities across Tools, Variables, Chatflow, Assistant, Dataset, and Custom Template endpoints
Notable features
  • Pipedream MCP integration
  • Browserless MCP integration
  • Email change confirmation flow
[email protected] Breaking risk
Breaking changes
  • HTTP security checks enabled by default — blocks localhost, 127.0.0.1, and internal addresses unless configured via HTTP_SECURITY_CHECK=false or HTTP_DENY_LIST
Security fixes
  • Default HTTP deny list for SSRF mitigation
  • Path traversal protections
  • HTTPS enforcement for user-provided URLs
Notable features
  • Azure Blob Storage support
  • AWS STS AssumeRole support
  • AgentFlow SDK (@flowiseai/agentflow v0.0.0-dev.2)
[email protected] Breaking risk
Security fixes
  • Mass assignment prevention in registration
  • DNS rebinding/TOCTOU vulnerability mitigation
Notable features
  • Azure Rerankers support
  • ChatCerebras v3.0 enhancement
  • Ollama Cloud integration
[email protected] Breaking risk
Breaking changes
  • Read/Write File Tools permanently removed — use Google Drive or Google Docs tools as alternatives
Security fixes
  • File path validation and traversal protections enhanced
[email protected] Mixed
Security fixes
  • Sensitive field sanitization in logger
  • Path traversal validation on chatId
Notable features
  • Teradata VectorStore support in DocumentStore
  • Fuzzy node search with ranking and matching
  • Northflank deployment option support
[email protected] Mixed
Security fixes
  • MCP security configuration validation
Notable features
  • Gemini Built-In Tools support
  • Teradata MCP server integration
  • OpenAPI Toolkit URL loading and selection

Beta — feedback welcome: [email protected]