Flowise 3.1.4 and RAGFlow 0.27.2 ship with unfixed advisories
The latest releases of self-hosted AI apps Flowise (3.1.4) and RAGFlow (0.27.2) still carry critical vulnerabilities with no patched version available. Dependency scanners miss them because the advisories lack CVE IDs and OSV.dev records.
- Flowise 3.1.4: six advisories from Sept 10, including SSO email takeover (CVSS 9.2)
- RAGFlow 0.27.2: any signed-in user can run another user's private agent
- Seven advisories have no CVE or OSV.dev entry — Dependabot and Trivy miss them
- RAGFlow 0.25.0+ already fixes Jinja2 injection, but the advisory doesn't say so
Read next
Security