Executive brief
FlowiseAI is a low-code platform for building LLM-powered applications. An authenticated admin user can inject malicious JavaScript into the Supabase RPC Filter component to execute arbitrary code on the server, potentially compromising the entire application, stealing environment secrets, or gaining remote shell access.
Technical details
The vulnerability is a code injection flaw (CWE-94) in the Supabase.ts component (packages/components/nodes/vectorstores/Supabase/Supabase.ts#L237) where user-supplied filter expressions are compiled and executed as JavaScript without sanitization, escaping, or sandboxing. An authenticated admin attacker can inject a malicious payload into the supabaseRPCFilter field that triggers arbitrary command execution via Node.js's execSync(). The attack requires admin authentication and the Supabase vector store to be enabled, but no additional user interaction is needed once triggered. An attacker can achieve full remote code execution, access sensitive environment variables like JWT secrets, establish reverse shells, and install persistent backdoors. The vulnerability was fixed in version 3.0.6.
Affected products
- FlowiseAI Flowise 3.0.5
Timeline
- 2025-09-15: disclosed
- 2025-09-15: patched: Fixed in version 3.0.6