chiprook
← Security
SecurityOctober 12, 2026, 03:31

Flowise 3.1.4 and RAGFlow 0.27.2 ship with unfixed advisories

The latest releases of self-hosted AI apps Flowise (3.1.4) and RAGFlow (0.27.2) still carry critical vulnerabilities with no patched version available. Dependency scanners miss them because the advisories lack CVE IDs and OSV.dev records.

Flowise 3.1.4 and RAGFlow 0.27.2 ship with unfixed advisories
#Flowise#RAGFlow
Read next
Security

Proton Mail left sender-spoofing flaw unfixed for 16 months

Security

CVE-2026-41264: A Regex Let Prompts Run Code in Flowise

Business

Jensen Huang and Lisa Su join Tsinghua University advisory board

AI

OpenAI forms AGMAI math advisory group, sparking confusion again