Skip to content
Agents tracked: 258 Downloads (7d): 219M up 6.1% GitHub stars: 5.5M VS Code installs: 148M Releases (7d): 327 Agent status: 1 with issues Updated Oct 7, 2026

Flowise changelog: what's new each month

Every stable Flowise release summarised by month: the highlights, new features, improvements, fixes and anything you need to act on. 3 months covered; the current month updates daily.

July 2026

1 release: 3.1.4

July brought security and validation improvements across Flowise, focusing on workspace isolation, authorization controls, and deny list enforcement.

Highlights

  • Enhanced tenant validation to prevent cross-workspace authorization issues
  • Implemented operator-controlled allowlist for custom MCP stdio commands
  • Added deny list checks for web scrapers and certain chat models

Improved

  • Workspace-level node loading now properly respects workspace boundaries
  • Session ID type validation strengthened

Fixed

  • Cross-workspace authorization vulnerability in OpenAI Realtime
  • Variable values incorrectly included in exports
  • Deny list not being checked in web scrapers
  • Deny list not being checked in certain chat models
  • Tenant validation issues that could allow unauthorized access

June 2026

1 release: 3.1.3

June brought security improvements and workflow enhancements to Flowise, along with new capabilities for integrating with MCP servers and extending the canvas interface.

Highlights

  • Chatflows can now be turned into MCP servers for broader integration possibilities.
  • Added client-side filtering for form input options in Start nodes.
  • Canvas actions can now be extended with optional custom buttons next to the validate button.
  • Flow change notifications now properly trigger when nodes or edges are deleted or duplicated.

New

  • Ability to convert chatflows into MCP servers.
  • Optional canvas actions to add custom buttons in the workflow editor.
  • Client-side filtering for Start node form input options.

Improved

  • Flow change notifications now fire for deleteNode, deleteEdge, and duplicateNode operations.
  • Agentflow component updated to latest development version.

Fixed

  • Clickjacking vulnerability patched.
  • Clean and Nuke script corrected.

April 2026

1 release: 3.1.2

April brought important security fixes addressing credential handling, cross-origin vulnerabilities, and data disclosure risks across multiple endpoints.

Highlights

  • Fixed credential data leak that could expose sensitive information
  • Patched cross-workspace chatflow disclosure vulnerability
  • Resolved mass assignment vulnerabilities in tools and variables endpoints
  • Improved MCP Server Config security
  • Fixed Markdown rendering limits on rich input

Improved

  • Enhanced MCP Server Config security
  • Session cleanup improved for MySQL-based session storage
  • Markdown rendering on RichInput now has appropriate limits

Fixed

  • Credential data leak
  • Mass assignment vulnerability in Tools endpoint
  • Mass assignment vulnerability in Variables endpoints
  • Chatflow query disclosure across workspaces
  • Session cleanup when using MySQL for session storage

Summaries are written automatically from the official release notes (full changelog ↗); check the original notes before relying on a detail. Flowise: pricing, features and alternatives · All changelogs