flowise-components@2.2.8 vulnerabilities

Flowiseai Components

Direct Vulnerabilities

Known vulnerabilities in the flowise-components package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • C
Arbitrary Code Injection

flowise-components is a Flowiseai Components

Affected versions of this package are vulnerable to Arbitrary Code Injection due to the unsafe implementation of a dynamic Function constructor. An attacker can execute arbitrary JavaScript code on the server by sending a crafted POST request.

How to fix Arbitrary Code Injection?

There is no fixed version for flowise-components.

*
  • C
Command Injection

flowise-components is a Flowiseai Components

Affected versions of this package are vulnerable to Command Injection via the Custom_MCP class. An attacker can gain unauthorized remote access and execute arbitrary operating system commands by sending crafted requests over the network. This is only exploitable if authentication is not explicitly configured.

How to fix Command Injection?

There is no fixed version for flowise-components.

>=0.0.0