I’m sharing an important security alert for those using Flowise on their servers.
INCIBE has published a notice about 10 critical vulnerabilities affecting Flowise.
These flaws, which include remote code execution, sandbox escape, credential theft, and full server compromise, affect versions 3.1.2 and earlier.
The solution is to update Flowise and flowise-components to version 3.1.3 or later immediately.
If you have Flowise deployed on OVHcloud, I recommend doing so without delay. Here is the full INCIBE notice: Multiple vulnerabilities in Flowise
Regards, colleagues ![]()
Sergio Turpín