CVE-2025-57164: Command Injection
Published Oct 17, 2025
·Updated
Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.
Affected Software
2 affected components
Flowise Flowise<=3.0.4
FlowiseAI Flowise=3.0.5
Event History
Oct 17, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-57164?
CVE-2025-57164 is rated as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-57164?
To fix CVE-2025-57164, upgrade to Flowise version 3.0.5 or later where the vulnerability is patched.
3
What software versions are affected by CVE-2025-57164?
CVE-2025-57164 affects Flowise versions up to and including 3.0.4.
4
What type of vulnerability is CVE-2025-57164?
CVE-2025-57164 is a remote code execution vulnerability resulting from unsanitized evaluation of user input.
5
Where can I find more information about CVE-2025-57164?
Detailed information about CVE-2025-57164 can be found in the project's repository and its security advisories.