🚨 Multiple Critical & High Vulnerabilities in FlowiseAI
• Critical Auth RCE via Custom JS Function (NodeVM sandbox escape)- GHSA-9rvc-vf7m-pgm2
• Credential Data Leak (encrypted secrets exposed) - GHSA-7g73-99r4-m4mj
• Multiple Mass Assignment flaws (cross-workspace takeover of Assistants, Templates, Datasets, Evaluators, etc.)- GHSA-78pr-c5x5-jggc, GHSA-728h-4mwj-f2p4, GHSA-wxrr-jp8m-qq7f, GHSA-mq53-pc65-wjc4 more
👉Affected: FlowiseAI <=3.1.1 | Upgrade to 3.1.2