people · May 18, 2026
Flowise Patches Arbitrary File Upload Vulnerability CVE-2026-30821
Share the canonical public link.
Endor Labs disclosed CVE-2026-30821 affecting Flowise, which allowed arbitrary file upload through MIME spoofing in the Custom MCP node. The vulnerability impacted versions prior to 3.0.13 and was fixed in the release tagged flowise%403.0.13. FlowiseAI addressed the issue via GitHub security advisory GHSA-j8g8-j7fc-43v6. Researchers noted the flaw enabled attackers to upload malicious files without proper validation in the drag-and-drop AI workflow builder.
Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)