flowise-components@3.0.8 vulnerabilities

Flowiseai Components

Direct Vulnerabilities

Known vulnerabilities in the flowise-components package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • C
Command Injection

flowise-components is a Flowiseai Components

Affected versions of this package are vulnerable to Command Injection via the Custom_MCP class. An attacker can gain unauthorized remote access and execute arbitrary operating system commands by sending crafted requests over the network. This is only exploitable if authentication is not explicitly configured.

How to fix Command Injection?

There is no fixed version for flowise-components.

>=0.0.0