Description
============================================================================= Security Advisory elttam
Topic: Flowise RCE via SQLite Record Manager Node
Module: FlowiseAI/Flowise Disclosed: 24-Ap
Recommendation
Update the flowise-components package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.1.2
- Patched version(s): 3.1.3
References
Could your website be exposed too?
SmartScanner can check your website for Flowise RCE via SQLite Record Manager Node and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation - CVE-2026-69264
- Flowise RCE via TypeORM DataSource - CVE-2026-69251
- Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure) - CVE-2026-43995
- Flowise: Authenticated RCE Via MCP Adapters - CVE-2026-40933


