Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.
| Software | From | Fixed in |
|---|---|---|
flowise
|
3.0.5 | 3.0.5.x |
flowise
|
3.0.5 | 3.0.6 |
| flowiseai / flowise | 3.0.5 | 3.0.5.x |