CVE-2026-70474
- EPSS 0.29%
- Veröffentlicht 04.08.2026 18:01:01
- Zuletzt bearbeitet 11.09.2026 21:07:42
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The authorize, callback...
CVE-2026-70473
- EPSS 0.25%
- Veröffentlicht 04.08.2026 17:56:50
- Zuletzt bearbeitet 11.09.2026 21:05:40
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenan...
CVE-2026-70472
- EPSS 0.25%
- Veröffentlicht 04.08.2026 17:46:05
- Zuletzt bearbeitet 14.09.2026 19:01:45
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without checking whet...
CVE-2026-70471
- EPSS 0.28%
- Veröffentlicht 04.08.2026 17:43:29
- Zuletzt bearbeitet 14.09.2026 19:09:15
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protected Variables A...
CVE-2026-70470
- EPSS 0.52%
- Veröffentlicht 04.08.2026 17:30:54
- Zuletzt bearbeitet 14.09.2026 19:19:38
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allo...
CVE-2026-69264
- EPSS 0.58%
- Veröffentlicht 04.08.2026 17:22:36
- Zuletzt bearbeitet 14.09.2026 19:20:36
Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to globalThis, whi...
CVE-2026-69263
- EPSS 0.27%
- Veröffentlicht 04.08.2026 16:54:36
- Zuletzt bearbeitet 14.09.2026 19:24:10
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, LD_LIBRARY_...
CVE-2026-69262
- EPSS 0.25%
- Veröffentlicht 04.08.2026 16:50:12
- Zuletzt bearbeitet 14.09.2026 19:41:55
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permiss...
CVE-2026-69259
- EPSS 0.35%
- Veröffentlicht 04.08.2026 16:05:19
- Zuletzt bearbeitet 14.09.2026 19:47:08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled add...
CVE-2026-69258
- EPSS 0.38%
- Veröffentlicht 04.08.2026 15:56:06
- Zuletzt bearbeitet 14.09.2026 19:47:46
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig...