NPM · AUGUST 2026 · CONFIRMED

Flowise npm Package Compromised via Pyodide Validator Bypass

GHSA-3HJV-C53M-58JJGHSA-52FH-8V99-63C2Severity: HIGH

The Flowise npm package has been compromised through a Unicode homoglyph bypass in the Pyodide validator, enabling remote code execution. Users of affected versions of flowise and flowise-components are at risk.

What happened

The compromise was facilitated by a Unicode homoglyph bypass in the Pyodide validator, allowing malicious code to be executed remotely. Affected versions of flowise include those introduced from version 0 up to and including 3.1.3, 3.1.0, 1.4.3, 1.8.2, 3.0.5, 3.0.8, 3.1.2, 2.1.4, 3.0.13, and 2.2.7-patch.1. For flowise-components, affected versions range from 0 up to and including 3.1.3, 3.1.0, 2.2.4, 3.0.8, 3.1.2, and 3.1.3.

To mitigate this threat, it is recommended to upgrade to the latest versions of flowise and flowise-components once they become available. Additionally, any custom code that interacts with Pyodide should be thoroughly reviewed for potential vulnerabilities.

For detailed version-specific information and fixes, consult the primary sources linked in the incident data. The severity of this threat is high, and immediate action is advised to prevent potential exploitation.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If flowise is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats