CVE-2026-70473
- EPSS 0.25%
- Veröffentlicht 04.08.2026 17:56:50
- Zuletzt bearbeitet 04.08.2026 20:16:54
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenan...
CVE-2026-70472
- EPSS 0.25%
- Veröffentlicht 04.08.2026 17:46:05
- Zuletzt bearbeitet 05.08.2026 16:17:02
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without checking whet...
CVE-2026-70471
- EPSS 0.28%
- Veröffentlicht 04.08.2026 17:43:29
- Zuletzt bearbeitet 04.08.2026 20:16:53
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protected Variables A...
CVE-2026-70470
- EPSS 0.52%
- Veröffentlicht 04.08.2026 17:30:54
- Zuletzt bearbeitet 04.08.2026 20:16:53
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allo...
CVE-2026-69264
- EPSS 0.58%
- Veröffentlicht 04.08.2026 17:22:36
- Zuletzt bearbeitet 04.08.2026 19:16:53
Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to globalThis, whi...
CVE-2026-69263
- EPSS 0.27%
- Veröffentlicht 04.08.2026 16:54:36
- Zuletzt bearbeitet 04.08.2026 18:16:56
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, LD_LIBRARY_...
CVE-2026-69262
- EPSS 0.25%
- Veröffentlicht 04.08.2026 16:50:12
- Zuletzt bearbeitet 05.08.2026 14:17:11
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permiss...
CVE-2026-69259
- EPSS 0.35%
- Veröffentlicht 04.08.2026 16:05:19
- Zuletzt bearbeitet 04.08.2026 19:16:53
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled add...
CVE-2026-69258
- EPSS 0.38%
- Veröffentlicht 04.08.2026 15:56:06
- Zuletzt bearbeitet 05.08.2026 16:17:01
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig...
CVE-2026-69257
- EPSS 0.25%
- Veröffentlicht 04.08.2026 15:51:47
- Zuletzt bearbeitet 04.08.2026 17:17:00
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 b...