CVE-2026-73604
- EPSS 0.28%
- Veröffentlicht 13.08.2026 11:28:10
- Zuletzt bearbeitet 13.08.2026 15:20:18
Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive data i...
CVE-2026-73603
- EPSS 0.32%
- Veröffentlicht 13.08.2026 11:28:09
- Zuletzt bearbeitet 14.08.2026 23:16:33
Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using store...
- EPSS 0.61%
- Veröffentlicht 13.08.2026 11:28:08
- Zuletzt bearbeitet 14.08.2026 21:17:57
Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command ...
- EPSS 0.44%
- Veröffentlicht 13.08.2026 11:28:08
- Zuletzt bearbeitet 13.08.2026 13:19:19
Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match ...
- EPSS 0.27%
- Veröffentlicht 13.08.2026 11:28:07
- Zuletzt bearbeitet 13.08.2026 15:20:15
Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile data by manipu...
- EPSS 0.33%
- Veröffentlicht 13.08.2026 11:28:06
- Zuletzt bearbeitet 13.08.2026 13:19:17
Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a static regex blocklist that can be bypassed throug...
- EPSS 0.39%
- Veröffentlicht 13.08.2026 11:28:06
- Zuletzt bearbeitet 14.08.2026 23:16:33
Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.rea...
- EPSS 0.28%
- Veröffentlicht 13.08.2026 11:28:05
- Zuletzt bearbeitet 14.08.2026 21:17:57
Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques. Attackers ca...
CVE-2026-73483
- EPSS 0.37%
- Veröffentlicht 13.08.2026 11:28:04
- Zuletzt bearbeitet 14.08.2026 23:16:33
Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-custom-function endpoint can escape the sandbox by ...
CVE-2026-73484
- EPSS 0.29%
- Veröffentlicht 13.08.2026 11:28:04
- Zuletzt bearbeitet 13.08.2026 15:20:15
Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit this to exfiltrate uploaded CSV data...