Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (11 days ago).

← Intel index

This coverage is stale.

Last updated May 18, 2026 (about 4 months ago).

people · May 18, 2026

Flowise Patches Arbitrary File Upload Vulnerability CVE-2026-30821

Share the canonical public link.

Share as image

Endor Labs disclosed CVE-2026-30821 affecting Flowise, which allowed arbitrary file upload through MIME spoofing in the Custom MCP node. The vulnerability impacted versions prior to 3.0.13 and was fixed in the release tagged flowise%403.0.13. FlowiseAI addressed the issue via GitHub security advisory GHSA-j8g8-j7fc-43v6. Researchers noted the flaw enabled attackers to upload malicious files without proper validation in the drag-and-drop AI workflow builder.

Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)

Supporting evidence